ASOS Says Data Breach Followed Social Engineering and Employee Credential Theft

Summary
ASOS says attackers impersonated a trusted contact to steal an employee’s login credentials and access information on third-party platforms. Names and contact details may have been exposed; payment data and passwords were not accessed.
Key points
- ASOS confirmed that an attacker impersonated a trusted contact to obtain an employee’s login credentials.
- The stolen credentials were used to access information on third-party platforms used by ASOS.
- Exposed information may include customers’ full names, contact details, and certain non-personal account-related information.
- ASOS says payment card information and account passwords were not accessed.
- The company locked down the affected platforms and is investigating with external experts, law enforcement, and regulators.
- ASOS says no customer account action is needed, advises caution with unexpected messages or calls, and has added security measures.
Article Details
- Victim Organization
- ASOS
- Incident Type
- Social engineering and employee credential theft leading to unauthorized access to third-party platforms and a customer data breach
- Data Types Exposed
- Full names
- Contact details
- Certain non-personal account-related information
- Affected Records
- Not disclosed
- Affected Data Size
- Not disclosed
- Operational Impact
- ASOS locked down the affected third-party platforms and launched an investigation with external experts, law enforcement, and regulatory authorities. ASOS stated that its website and app remained safe to use throughout the incident.
- Ransom Or Extortion
- On 2026-10-06, malicious push notifications sent through the ASOS app alleged customer data theft and urged company staff to engage on Telegram. No specific ransom demand was disclosed.
- Claim Status
- confirmed