bleeping-computer · Crawled Oct 8, 2026
ASOS links data breach to social engineering attack, credential theft
1 IoCs
Read original article ↗
AI Summary
ASOS confirmed a data breach resulting from a social engineering attack in which an attacker impersonated a trusted contact to steal an employee's login credentials. The compromised credentials were used to access third-party platforms used by ASOS, leading to the exposure of customers' full names, contact details, and certain non-personal account-related information. The threat actor, identifying itself as 'Xuanye Group,' sent malicious in-app notifications to users, but ASOS confirmed that payment card information and account passwords were not accessed.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | telegram[.]org | Details → |