ASOS has confirmed that a data breach at the UK online fashion retailer stemmed from a social engineering attack in which hackers impersonated a trusted contact to steal an employee's login credentials. The company said the stolen credentials were then used to reach information stored on certain third-party platforms it relies on. ASOS locked down the affected platforms and opened an investigation with outside experts, law enforcement, and regulatory authorities.

The retailer, which sells clothing, footwear, accessories, and beauty products to customers worldwide, notified users of the incident through its security notification. In a message to customers, ASOS said the exposed data involved basic personal information and contact details. The company said payment card information and account passwords were not accessed.

The breach surfaced publicly on October 6, 2026, when ASOS customers received a push notification through the ASOS app on their mobile devices. The message alleged customer data theft and urged the company's staff to engage with the sender on Telegram. A threat actor using the name "Xuanye Group" took credit for the data theft, claiming it did not include payment information.

ASOS later published a statement on its website confirming the breach. The company told customers no action is required on their accounts and that its website and app were at all times, and remain, safe to use. It also advised customers to be wary of unexpected messages or calls that appear to come from ASOS.

ASOS said it would never ask customers to provide passwords, security codes, or payment details through an unsolicited message or call. The company said its investigation is ongoing and that it will share further updates if significant findings come to light. ASOS added that it has already put additional security measures in place to prevent similar incidents.

The retailer has not disclosed how many customers were affected, and BleepingComputer reported that it had requested a figure without receiving one. For US consumers who shop ASOS, the company's guidance is unchanged: no account action is needed, but unsolicited requests for credentials or payment data should be treated as suspicious.

More cybersecurity news from TechManNews.