ASOS Says Data Breach Followed Social Engineering and Employee Credential Theft

· Original article ↗

Summary

ASOS says attackers impersonated a trusted contact to steal an employee’s login credentials and access information on third-party platforms. Names and contact details may have been exposed; payment data and passwords were not accessed.

Key points

  • ASOS confirmed that an attacker impersonated a trusted contact to obtain an employee’s login credentials.
  • The stolen credentials were used to access information on third-party platforms used by ASOS.
  • Exposed information may include customers’ full names, contact details, and certain non-personal account-related information.
  • ASOS says payment card information and account passwords were not accessed.
  • The company locked down the affected platforms and is investigating with external experts, law enforcement, and regulators.
  • ASOS says no customer account action is needed, advises caution with unexpected messages or calls, and has added security measures.

Article Details

Victim Organization
ASOS
Incident Type
Social engineering and employee credential theft leading to unauthorized access to third-party platforms and a customer data breach
Data Types Exposed
  • Full names
  • Contact details
  • Certain non-personal account-related information
Affected Records
Not disclosed
Affected Data Size
Not disclosed
Operational Impact
ASOS locked down the affected third-party platforms and launched an investigation with external experts, law enforcement, and regulatory authorities. ASOS stated that its website and app remained safe to use throughout the incident.
Ransom Or Extortion
On 2026-10-06, malicious push notifications sent through the ASOS app alleged customer data theft and urged company staff to engage on Telegram. No specific ransom demand was disclosed.
Claim Status
confirmed

MITRE ATT&CK

Threat Actors

Products

Countries

Industries

Related Articles