ASOS Confirms Data Breach Linked to Stolen Employee Credentials
ASOS confirmed attackers used stolen employee credentials to access customer account data via third-party platforms.
UK retailer ASOS told customers on October 8 that personal and account data was accessed in an October 6 breach. The attacker impersonated a trusted contact to steal an employee’s credentials, then used them on third-party customer platforms and sent a push notification claiming a Snowflake compromise. ASOS said payment data was not taken and operations continued; Snowflake said its platform was not compromised. Actor Xuanye Group told the BBC a Simon AI instance was the access path, and a sample reportedly included names, contact details, customer numbers, and search history.