Asos has confirmed that hackers accessed personal data of some customers after tricking an employee into sharing login credentials. The online fashion retailer disclosed the breach following a push notification sent to customers via its app on Tuesday, which contained a message claiming responsibility for the hack and threatening to leak data unless a ransom was paid.
According to Asos, an “unauthorised party” gained access to an employee account by impersonating a trusted contact, enabling the attackers to access information stored on third-party platforms used by the company. The compromised data included millions of customers’ names, delivery and email addresses, phone numbers, and recent search histories on the Asos app. Asos said no payment card details or account passwords were accessed during the incident.
The push notification directed customers to a Telegram channel operated by the hackers, who identified themselves as the Xuanye Group. The group claimed to have fully compromised Snowflake, a US-based cloud data service provider used by Asos, and issued a two-week ultimatum to engage with them or face data leakage. Snowflake, however, stated it had found no evidence that its systems had been breached.
Asos responded by immediately locking down the affected third-party platforms and launching a comprehensive investigation with the assistance of both internal and external cybersecurity experts. The company is cooperating with law enforcement and regulatory authorities as it continues to assess the full scope of the breach.
In communications with customers, Asos reassured users that their website and app remain safe to use and advised vigilance against unsolicited messages or calls purportedly from the retailer. The company emphasized that it would never ask customers to share passwords, security codes, or payment information through unexpected contact.
Security experts, while noting the unusual nature of the Xuanye Group—which had not been previously identified in cybercrime circles—warned that the attack could damage customer trust at a critical time. Asos, which experienced significant growth during the pandemic-era surge in online shopping but later faced a decline, had recently shown signs of recovery under CEO José Antonio Ramos Calamonte, with shares rising sharply over the past year.
The incident follows a series of cyberattacks on UK retailers and brands in recent years, highlighting ongoing vulnerabilities in the retail sector’s cybersecurity defenses. Analysts suggest that efforts to contain damage and restore customer confidence will be crucial for Asos’s continued recovery and growth trajectory.
