ASOS confirms data breach following social engineering attack on employee credentials
UK online fashion retailer ASOS notified customers that personal account data was accessed after an attacker impersonated a trusted contact to compromise employee credentials.
FTMQ Security, written by our newsroom0 views
UK online fashion retailer ASOS has confirmed a data breach following a cyber security incident on October 6. In an email sent to customers on October 8, the company stated that personal and customer account data was accessed by an unauthorized third party, according to InfoSecurity Magazine. InfoSecurity Magazine and Global Banking and Finance Review both report that the breach involved unauthorized access to personal customer information. [4][5]
InfoSecurity Magazine and SecNews.gr report that the breach occurred after an attacker gained access to an employee account by social engineering, specifically by impersonating a trusted contact to obtain log in credentials. InfoSecurity Magazine added that the compromised credentials were used to access third-party platforms used by the company. Attackers claimed that the compromise involved the marketing platform Simon AI. [4][8]
According to shattered.io, no passwords were hit during the breach. InfoSecurity Magazine further reported that payment information was not compromised during the incident and that ASOS business operations were not affected. [1][4]
NewsCord reports that the exposed customer information included names, addresses, phone numbers, email addresses, and customer numbers. Cybersecurity Insiders and GBHackers News reported that attackers have sent threatening messages directly to ASOS customers following the data leak. [2][9][11]
In short
- ASOS confirmed a data breach after discovering unauthorized access to personal customer account data on October 6.
- The breach occurred when an attacker social engineered an employee by impersonating a trusted contact to obtain log in credentials.
- ASOS confirmed that payment information and passwords were not compromised in the incident.
- The exposed data includes customer names, email addresses, physical addresses, phone numbers, and customer numbers.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ASOS Data Breach Confirmed: Names Leaked, 0 Passwords Hitshattered.io, 1h ago (the report this story comes from)
- [2]ASOS Data Breach: Hackers begin sending threatening messages to CustomersCybersecurity Insiders, 12h ago
- [3]Advantest Data Breach Confirmed Eight Months After AttackSafestate, 4h ago
- [4]ASOS Confirms Data Breach Linked to Stolen Employee CredentialsInfoSecurity Magazine, 11h ago
- [5]ASOS Cyber Hack: Personal Data Accessed in UK Cybersecurity BreachGlobal Banking & Finance Review, 14h ago
- [6]Lawson Reports Data Breach Affecting Over 2.15 Million Records; Daiichi Kosho Also Hit With Up to 8.72 Million Potentially ExposedBigGo Finance, 12h ago
- [7]Leaked Data Exposes Law Firms’ Ransom PaymentsSilicon UK, 16h ago
- [8]ASOS: Social Engineering Attack Behind Data LeakSecNews.gr, 10h ago
- [9]ASOS Hacked as Attackers Abuse Customer Notification Platform to Threaten Data LeakGBHackers News, 1d ago
- [10]Snowflake Denies ASOS Breach as 165-Firm Echo Grows [2026]https://tech-insider.org/, 1d ago
- [11]Asos Says Hackers Accessed Names, Addresses, Phone Numbers, Emails, Customer Numbers: 13 outlets comparedNewsCord, 11h ago
Background
- [12]Lime Crime on Wikipedia
- [13]Internet leak on Wikipedia
- [14]Password (American game show) on Wikipedia
Our newsroom writes these reports with the help of software, from the 14 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
More in Data Breaches
- Coupang files lawsuits over 620 billion won data leak fine1h ago
- Russia aligned group upgrades MATCHBOIL malware used against Ukrainian targets1h ago
- OT Coalition Urges CISA to Mandate Security Standards for Federal Systems1d ago
- Hackers hide VBScript payloads in browser caches via fake CAPTCHAs2d ago
- New Linux Backdoors Target Telecom Appliances in South Korea and Taiwan3d ago
- ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes3d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.