
ASOS has confirmed that a recent security incident, which resulted in unauthorized push notifications sent to its global customer base, was the direct result of a social engineering attack against an employee. The fashion retailer disclosed that the breach compromised specific categories of customer data, including names and recent search histories, after an unauthorized party successfully impersonated a trusted contact to steal internal login credentials.
The security failure became public on October 6, 2026, when ASOS mobile app users began receiving notifications stating “ASOS hacked.” These messages directed recipients to a Telegram channel controlled by the attackers. While the initial notifications caused immediate confusion, subsequent investigations revealed that the threat actor—identifying as the “Xuanye Group”—had gained access to third-party communication platforms rather than the company’s core internal databases.

The Impact of Social Engineering
The breach originated from a successful credential theft. According to ASOS, the attacker used social engineering tactics to manipulate an employee into providing their credentials. By impersonating a known or trusted entity, the actor bypassed standard security protocols to gain a foothold in the company’s administrative tools. This single compromised account granted the Xuanye Group access to the systems ASOS uses to manage customer messaging and push notifications.
The incident mirrors a broader trend of credential-theft campaigns targeting third-party service providers. While ASOS and its service partners report that core infrastructure remained secure, the access to customer-facing communication tools allowed the attackers to exploit the brand’s direct line to its users’ mobile devices.
Stolen Search Histories and Contact Details
ASOS confirmed the specific scope of the data accessed during the intrusion. The stolen information includes:
- Full names and email addresses
- Delivery addresses and phone numbers
- Recent customer search histories (e.g., specific queries such as “glamorous wide fit”)
The theft of search history is particularly concerning for privacy advocates, as it provides attackers with intimate knowledge of consumer preferences and habits. This data can be leveraged to create highly personalized phishing campaigns that appear more legitimate than standard spam. ASOS has emphasized that highly sensitive information, including account passwords and full payment card details, was not accessed during the incident.
Market Reaction and Financial Fallout
The public nature of the hack, characterized by the hijacked notifications, had an immediate impact on the company’s valuation. Following the emergence of the breach and the subsequent Telegram extortion attempts by the Xuanye Group, ASOS shares on the London Stock Exchange saw a significant decline, dropping by nearly 10%.
The incident highlights the vulnerability of large-scale digital platforms to “human-in-the-loop” attacks. Even with robust technical defenses at the database level, the exploitation of a single employee’s trust allowed an external group to hijack a global communication system and extract significant amounts of personal data.


