bleeping-computer · Crawled Oct 8, 2026

ASOS links data breach to social engineering attack, credential theft

1 IoCs
Read original article ↗

AI Summary

ASOS confirmed a data breach resulting from a social engineering attack in which an attacker impersonated a trusted contact to steal an employee's login credentials. The compromised credentials were used to access third-party platforms used by ASOS, leading to the exposure of customers' full names, contact details, and certain non-personal account-related information. The threat actor, identifying itself as 'Xuanye Group,' sent malicious in-app notifications to users, but ASOS confirmed that payment card information and account passwords were not accessed.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain telegram[.]org Details →