ASOS breach: stolen employee login exposed customer contacts
ASOS employee credential theft customer contacts

ASOS breach: stolen employee login exposed customer contacts

UK retailer ASOS has confirmed that a social-engineering attack, not a break of its own website, is behind this week's customer-data incident. One stolen employee login was enough to reach third-party platforms and to push a rogue notification through the ASOS app.

What happened

On 6 October 2026 customers received an in-app push that claimed the company had been compromised and told staff to engage on Telegram. ASOS later told BleepingComputer that an unauthorised party gained an employee account by impersonating a trusted contact, then used those credentials on certain third-party platforms.

The company says the exposed set is full names and contact details. It says payment card data and account passwords were not accessed, and that the website and app remain safe to use. The actor calling itself Xuanye Group claimed a larger haul. Treat that claim as unconfirmed. The confirmed path is identity theft of a staff login, then abuse of a customer-messaging platform.

Who is affected

ASOS customers whose names and contact details sat on the third-party platforms the stolen login could reach. ASOS has not published a victim count. Anyone who received the rogue push should assume their contact details may be in criminal hands, even if they never tapped the notice.

  • Confirmed exposed: full names and contact details.
  • ASOS says not exposed: payment cards and account passwords.
  • The app itself was the delivery channel for the attacker's message, which means the messaging platform was in scope.

What to do now

Treat unexpected ASOS calls, texts, and app notices as phishing, and lock down every staff account that can send customer notifications. Phishing-resistant MFA on marketing, CRM, and data-platform logins would have blocked this path. If you run a similar stack, review who can impersonate your brand in push, email, and SMS, and alert customers only through a channel you still control.

Source: BleepingComputer, ASOS links data breach to social engineering attack, credential theft.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-105192: LMCache CVSS 9.8 RCE still unpatched
LMCache unauthenticated ZMQ remote code execution