ASOS confirms customer data breach caused by stolen employee credentials
ASOS has confirmed that customer names and contact details were accessed after an employee's login credentials were stolen through social engineering. This data can't be used to pay in your name, but it can help fraudsters write convincing scam messages.

What ASOS has confirmed
On 8 October 2026, Bleeping Computer, a site that covers cybersecurity, published ASOS’s latest security notice to its customers. ASOS is a British online fashion retailer that sells clothing, shoes, accessories and beauty products worldwide. The notice sets out the scope of the data breach the company had acknowledged a few days earlier.
According to the notice, three types of information were exposed:
- full names;
- contact details;
- some account-related information, which the company describes as non-personal.
ASOS also says the attackers did not get access to payment card data or account passwords. The number of affected customers is still unknown: Bleeping Computer asked the company and had not received an answer when it published.
How the attackers got in
The notice says the intrusion did not start with a technical vulnerability. It started with manipulation. An unauthorised person pretended to be a trusted contact, approached an ASOS employee and obtained their login credentials. They then used those credentials to reach information held on some third-party platforms that the company uses.
ASOS says it has locked down the affected platforms. It has opened an investigation with support from outside experts, law enforcement and regulators, and says it has already strengthened its security measures to stop a similar incident from happening again. The investigation is still under way, and ASOS has committed to sharing any significant new findings.
The incident became public on 6 October 2026. That day, customers received a notification in the ASOS mobile app announcing a data theft and asking company staff to get in touch on Telegram. The group behind the message, which calls itself “Xuanye Group”, claimed to have stolen customer data but not payment information. ASOS then confirmed the breach in a statement on its website, describing the exposed data as “basic” personal information and contact details. The company also says its website and app stayed safe to use throughout and still are.
What affected customers should do
ASOS says you don’t need to take any action on your account. Passwords were not among the exposed data, so the company is not asking customers to reset them.
It does, however, urge caution with any unexpected message or call that claims to come from ASOS. The company reminds customers that it never asks for passwords, security codes or bank details in a message or call you didn’t request.
A name combined with contact details is enough to make a fraudulent message more convincing. If you get a message about your account, an order or a refund, don’t use the link or phone number it contains. Open the ASOS app or website yourself instead. Treat any request for a code sent by text message, or for card details, as a fraud attempt, since the company says it never asks for them this way.
The whole breach started with an employee who thought they were talking to someone they could trust. Customers now need to watch for the same trick.
Sources (1)
- ASOS links data breach to social engineering attack, credential theftbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


