INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ASOS suffers data breach linked to social engineering attack

| 2026-10-08 11:42 HIGH HIGH DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A recent data breach at UK-based online fashion retailer ASOS was caused by a social engineering attack in which hackers stole an employee's login credentials and used them to access information on third-party platforms. The attackers, claiming to be from "Xuanye Group", impersonated a trusted contact to obtain the employee's log-in credentials, then accessed certain third-party platforms used by ASOS. This incident affected some customers, with exposed personal data including full names, contact details, and non-personal account-related information. ASOS has confirmed that payment card information or account passwords were not accessed. The company launched an investigation with external experts, law enforcement, and regulatory authorities after discovering the breach on October 6, 2026, and has since taken steps to implement additional security measures to prevent similar incidents in the future.
Technical Mitigations AI-generated
• Use multi-factor authentication (MFA) to protect employee accounts and prevent credential theft. • Implement a robust security notification system that alerts employees of suspicious activity, such as the push notifications sent by ASOS customers. • Regularly monitor third-party platforms used by ASOS for unauthorized access attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
FIVE_EYES FIVE_EYES retailretail
Incident Timeline
‎October 6, 2026
Malicious actors from the "Xuanye Group" sent phishing-like in-app notifications to ASOS customers on October 6, 2026.
industry Retail
organisation “Xuanye Group
organisation NFL
organisation CHANEL
‎2026/10/08
Threat actors impersonated a trusted contact to obtain an ASOS employee's login credentials, which were then used to access information on third-party platforms.
organisation ASOS
organisation BleepingComputer
Intelligence Sources