2 Remove Virus

ASOS reveals stolen employee credentials led to customer data breach

British fashion retailer ASOS has revealed that its recent data breach began with a social engineering attack in which hackers tricked an employee into handing over their account credentials.

 

 

The company disclosed the findings on October 8, two days after customers received an unauthorized notification through the official ASOS mobile app. The incident exposed customer information and raised questions about how attackers gained control of a communication channel used by the retailer.

According to ASOS, the attackers impersonated a trusted contact to obtain an employee’s login details. They then used the compromised account to access third-party platforms that ASOS relies on to communicate with customers.

This technique, known as social engineering, involves manipulating someone into revealing sensitive information or granting access. Rather than directly exploiting a software vulnerability, criminals take advantage of a person’s trust to bypass security protections.

ASOS confirmed that the attackers accessed basic personal information, including customer names and contact details. Certain non-personal account information was also exposed, with reports indicating that this included customers’ recent shopping searches.

However, the retailer said its investigation found no evidence that customer account passwords or payment-card information were compromised.

The attack first became visible on October 6 when customers received a push notification claiming ASOS had been hacked. The message threatened to leak information unless the company contacted the attackers through Telegram.

A group calling itself Xuanye Group claimed responsibility and alleged that it had compromised ASOS’s Snowflake environment. That specific claim has not been verified, and Snowflake has said it found no evidence that its own platform was compromised.

Following the incident, ASOS restricted access to the affected third-party platforms and launched an investigation involving internal and external cybersecurity specialists. The company is also cooperating with law enforcement and regulatory authorities.

ASOS has assured customers that its website and mobile app remained safe to use throughout the incident. It has not asked users to reset their passwords or take immediate action on their accounts.

Nevertheless, the retailer warned customers to remain cautious about unexpected calls, emails or text messages claiming to come from ASOS. Exposed contact information could make targeted phishing attempts more convincing.

ASOS says it will contact customers directly if its continuing investigation identifies any need for additional support or protective action.