A breach that started with a phone call or a message, not an exploit
ASOS has now explained how attackers got into its customer data, and the explanation is ordinary. The UK online fashion retailer says an outsider pretended to be a trusted contact, persuaded an employee to hand over login credentials, and then used that employee's account to get into information held on third-party platforms the company relies on.3 In its notice to customers, ASOS said it locked down the affected platforms and opened an investigation with outside experts, law enforcement and regulators.31
None of the reporting describes a zero-day, an unpatched server or a novel exploit chain. Coverage of the intrusion consistently describes it as social engineering rather than an attack on a software vulnerability.1418 For security teams that measure their exposure in CVEs and patch cycles, that is the main lesson. Over the past two years, the most damaging retail incidents have depended on persuading people, and this one fits that pattern.
How the week unfolded
The incident became public in an unusual way. At around 10 a.m. on Tuesday, October 6, ASOS app users received a push notification addressed to the company's data protection officer and IT team. It claimed the attackers had "fully compromised" the company's Snowflake instance and warned that the data would leak unless ASOS engaged with them.72 The message linked to a Telegram channel run by a group calling itself the Xuanye Group.17 Bloomberg-sourced reporting said the group had no previous record of attacks and appeared to have set up its Telegram presence specifically to promote this claim.7
ASOS confirmed several hours later that names and contact details may have been accessed through third-party communication platforms. It said it did not believe payment cards or passwords had been reached.7 The market reacted quickly. ASOS shares fell as much as 15% in London, their largest intraday drop since May 2023.7 By Thursday, after the company had apologized and explained how the breach happened, the stock had recovered some ground, rising as much as 5.7% during the session.9
The Thursday update, which followed what the company called a 48-hour investigation, gave the social engineering explanation. It also confirmed that delivery and email addresses, names and phone numbers had been accessed, along with "certain non-personal account related information."1
What was taken, and why the description changed
The biggest gap in the coverage is between how ASOS described the stolen data and what the attackers apparently hold. The company first called it "basic" personal information.3 On October 7, the hackers sent BBC News a sample of the data. According to reports of that sample, it shows a wider haul: names, home addresses, phone numbers, emails, customer numbers and search data.5 Malwarebytes, also drawing on the BBC's findings, adds dates of birth and details such as when each customer first started using ASOS.10 The Guardian reported that recent search terms were included, giving examples such as "glamorous wide fit" and "Asos petite."1
This is not a minor detail. Search history is behavioral data, and it could make a phishing message much more convincing. One security executive told the Guardian that ASOS regularly emails customers about items they have searched for, so attackers could copy those emails almost exactly.1 Malwarebytes questioned whether the company's early reassurances matched the evidence.10
The two accounts are not strictly contradictory. "Non-personal account-related information" can reasonably cover search logs. However, the early wording understated how useful the data is to fraudsters. Customers are right to rely on the more detailed BBC-based picture.
The size of the breach is still unknown. ASOS has not said how many customers are affected, despite repeated press questions.315 The Guardian and Cyber Magazine both describe the data as covering millions of customers.15 Reported figures for the company's customer base differ slightly. One outlet cites 17 million customers from ASOS's website, while Bloomberg's reporting gives 16.4 million active customers in more than 100 markets as of the end of fiscal 2026.27 The UK's National Cyber Security Centre has told all ASOS customers to assume their data was affected, whether or not they received the rogue notification.17 That is stronger advice than ASOS's own message that customers do not need to do anything.3
Snowflake, Simon AI and the third-party question
The attackers named Snowflake, which made the incident look like a repeat of the 2024 wave of Snowflake-linked breaches. Snowflake has denied that its platform was compromised.717 The group later told the BBC it got in through Simon AI, a customer personalization platform built on Snowflake that ASOS uses.105 Several reports refer to the attackers' claim that Simon AI was the entry point.16
The most likely explanation is that a stolen employee login gave access to a connected marketing and data platform where customer records were stored. In that case no vendor's core infrastructure was breached. Malwarebytes says plainly that the reporting does not show a vulnerability in Snowflake or Simon AI.10 Neura CybIntel likewise points out that a company using a cloud service does not mean the provider itself was breached.14
Two important questions remain open. TechCrunch notes it is unclear whether the ASOS-run environment had multi-factor authentication. It is also unknown how the attackers took over the app's push notification system, which is usually run by a separate third-party service.2 If MFA was missing, or could be bypassed through a social engineering flow, this would match a familiar pattern: attackers using valid credentials against a data store that a single password protected. That is analysis, not confirmed fact, but the open questions point that way.
The new extortion tactic
The security community has paid the most attention to the hijacked notification. Sygnia's Avi Dayan called it a significant shift in extortion tactics. In his view, attackers are moving from private negotiation to public pressure, using a company's own customers as leverage.7 Sectigo's Jason Soroko said anyone who can send messages through a trusted app can cause harm without proving any data was stolen.7
The threat has since become explicit. The Xuanye Group told The Telegraph it wants a ransom in exchange for deleting the data and has given ASOS two weeks to make contact.9 ASOS has not said whether it will pay.910 TechTimes notes a similar case at Betterment earlier this year, where attackers abused a third-party marketing platform to send customers a crypto scam.6 That comparison suggests marketing technology, the tools that hold customer data and can message customers directly, is becoming a preferred target.
No encryption or system disruption has been reported, so this is not ransomware in the traditional sense. It is data-theft extortion, combined with a public campaign through the company's own app. Attackers can run this kind of operation without deploying malware at all.
Why it matters beyond ASOS
ASOS is the latest British retailer to be hit, after Marks & Spencer, which had months of disruption following last year's attack.717 Security researcher Kevin Beaumont compared ASOS's communications to the Co-op and M&S incidents. He criticized the roughly five-hour gap before a full statement and said companies facing young, opportunistic attackers need better crisis plans.10 The commercial impact is real. Bloomberg Intelligence analyst Charles Allen said the hack could slow ASOS's efforts to rebuild sales and its customer base.1 ASOS has said it holds cyber insurance and that it is too early to judge the effect on trading.7
The practical conclusion is about identity security. Stolen credentials gave the attackers access to a data platform and the company's customer messaging in one step. Defenses based on phishing-resistant MFA, least-privilege access to vendor platforms and monitoring of customer messaging systems would have made that harder, as several analyses argue.1412 Patching remains essential, but it would not have stopped an employee who was talked into handing over a password.
For customers, the main risk now is follow-up scams. ASOS says it will never ask for passwords, security codes or payment details in an unsolicited message.1 With search histories in criminal hands, a message that mentions what you recently browsed is no proof that it came from ASOS.10 The investigation is continuing, and the attackers' deadline is approaching.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.
Sources
- 01Asos says customers’ names, contact details and search histories hacked — theguardian.com
- 02Asos confirms breach of customer data after hackers send rogue app notification — techcrunch.com
- 03ASOS links data breach to social engineering attack, credential theft — bleepingcomputer.com
- 04Asos confirms breach of customer data after hackers send rogue app notification — finance.yahoo.com
- 05The ASOS Data Breach Exposed Millions of Customers' Details — cybermagazine.com
- 06ASOS Data Breach Exposes Customer Information After Hackers Hijack In-App Notifications — techtimes.com
- 07ASOS Says Cyberattack May Have Compromised Customer Data — insurancejournal.com
- 08ASOS Confirms Data Breach After Rogue App Alert — quasa.io
- 09Asos says hackers tricked employee to access customer data — telegraph.co.uk
- 10ASOS breach update: Hackers stole customer details and shopping searches — malwarebytes.com
- 11ASOS Data Breach 2026: Cybersecurity Incident Analysis of Third-Party Compromise and Social Engineering Attack — rescana.com
- 12ASOS links data breach to social engineering attack… — radar.offseq.com
- 13ASOS Customer Data Breach Exposes Personal Information ... — neuracybintel.com
- 14ASOS Data Breach Exposed: Social Engineering Attack and Credential Theft Revealed — news4hackers.com
- 15ASOS confirms data breach following social engineering attack on employee credentials — security.ftmq.com
- 16Asos data breach traced to social engineering attack — finance.yahoo.com
- 17ASOS Data Breach: 1 Employee Account, 0 ICO Filing [2026] — tech-insider.org
- 18ASOSは、データ漏洩の原因をソーシャルエンジニアリング攻撃および認証情報の盗難にあると指摘している - PRSOL:CC — prsol.cc
- 19ASOS confirms breach after hackers pushed 'HACKED' app alerts - Circuit Mosaic — circuitmosaic.com