LeadershipReports disagree2 publishers3 min readPublished
Asos traces its data breach to one employee fooled by a fake trusted contact
Asos said hackers obtained an employee's login by posing as a trusted contact, then reached customer names and contact details on third-party platforms. The shares fell on the hackers' app alert two days before Asos explained it. For a board, that puts staff checks and disclosure speed inside the same risk.
The Board Room · Leadership desk

What happened
- Hackers announced the breach on Tuesday through a push notification on Asos's own app, linking to a Telegram channel run by a group calling itself Xuanye Group.
- Asos said it locked down the affected platforms and referred the incident to law enforcement and regulatory authorities.
- Shares fell more than 13% by City AM's count and about 10% by the Guardian's on the day the hackers' alert went out.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure A vendor can report its platform intact while a customer's account on it is emptied with valid credentials. The reach of each staff login inside outside tools sets how much one con exposes.
- cost Shareholders took most of the loss before Asos had said anything, and confirming that no payment data was taken won back only part of it.
- decision An attacker who controls a company's own customer channel sets the disclosure clock. Boards have to decide in advance how fast a factual holding statement can go out.
The con worked on one person, and the damage grew with what that person's login could open. Asos described the sequence in its Thursday statement: "We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos." [1] One employee account led into more than one outside platform.
The hackers' own notice named one of those platforms. It read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." [7] A Snowflake spokesperson said the company found "no compromise" of its platform [8]. Both statements can be true. A vendor's systems can be intact while a customer's account on them is entered with valid credentials, and Asos's statement refers only to "certain third-party platforms" [1]. City AM describes Snowflake as a cloud platform used to process data such as clothing sizes and body measurements that also lets users send notifications to clients' phones [9]. If the hackers' claim is accurate, the login that exposed customer data also gave them Asos's channel to its customers' phones [3].
On this record, the first failure was human [1]. Asos's statements do not say whether the stolen credentials were protected by a second authentication factor, or why one employee's access extended to customer contact data and a notification tool [1]. In my view a person and an access design failed together here: the impersonation produced the credentials, and the permissions let them reach several platforms. City AM noted that IT workers at Marks and Spencer were tricked by hackers who got into that retailer's systems last year [15].
The share price reacted to the hackers' announcement, before anyone outside knew how they got in. Asos made its first announcement on Thursday morning [5], after what the Guardian called a "detailed, 48-hour investigation" [6]. City AM put the fall at more than 13% [18]. The Guardian put it at about 10% [19]. After the statement the shares rose 4% to 469p [13]. Taken back to back, with no other moves between them, a 13% fall and a 4% rise leave the stock about 9.5% below where it started [16]; on the Guardian's figure, about 6.4% below [17]. City AM wrote that the sell-off cast doubt on the company's ability to continue its turnaround plan [20].
The trade-off for a board is speed of disclosure against accuracy. Here the attackers set the timing, by publishing through Asos's own app to thousands of users, according to the Guardian [4]. When Asos did speak, it was specific: names and contact details accessed, no payment information or passwords [2], platforms locked down and the case referred to law enforcement and regulators [10]. It also warned customers against the same technique that worked on its employee: "Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call." [14]
This quarter's decision for an operator is how quickly a factual holding statement can go out once an attacker goes public, and who verifies a "trusted contact" before credentials change hands [1]. Next quarter's consequence arrives when Asos's investigation ends and it contacts customers directly "where we believe additional information, support or action may be required" [11].
What to watch
- Whether Asos names the third-party platforms involved and says whether the stolen login was protected by a second authentication factor.
- How many customers Asos contacts directly when its investigation ends, and any action from the regulators it notified.
- Whether the Xuanye Group publishes data once its stated "designated period" runs out.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Asos said: "We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos."
ReportedSupportedSource: Asos statement to customers, reported by City AM and the Guardian2 sources— create a free account to open themView cited source - [2]
Asos confirmed basic personal information of customers, including names and contact details, was accessed; payment card details and passwords were not accessed.
ReportedSupportedSource: Asos, via the Guardian2 sources— create a free account to open themView cited source - [3]
On Tuesday hackers published a push notification on the Asos app claiming to have hacked the company and threatening a data leak; it linked to a Telegram channel where a user named 'Xuanye Group' posted.
- [4]
Thousands of users of the Asos app received the notification on Tuesday.
- [5]
Asos told customers on Thursday morning, in its first announcement since the hack, that it had launched a detailed investigation.
- [6]
Asos carried out a "detailed, 48-hour investigation" before confirming what was accessed.
- [7]
The notification read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
ReportedSupportedSource: Hackers' push notification, quoted by City AM2 sources— create a free account to open themView cited source - [8]
A Snowflake spokesperson said on Tuesday that it found "no compromise" of its platform.
ReportedSupportedSource: Snowflake spokesperson, via City AM2 sources— create a free account to open themView cited source - [9]
Snowflake is a cloud platform used to process data like clothing sizes and body measurements, and it also lets users send notifications to clients' phones.
- [10]
Asos said the affected platforms were immediately locked down and it was working with the relevant law enforcement and regulatory authorities.
ReportedSupportedSource: Asos, via the Guardian and City AM2 sources— create a free account to open themView cited source - [11]
Asos said: "Once our investigation is complete, we will contact customers directly where we believe additional information, support or action may be required."
ReportedSupportedSource: Asos, via City AM2 sources— create a free account to open themView cited source - [12]
The Xuanye Group said the customer information it obtained is "safe" on its server and "will not be touched for a designated period".
ReportedSupportedSource: Xuanye Group Telegram post, via City AM2 sources— create a free account to open themView cited source - [13]
Shares in FTSE-250-listed Asos rose four per cent to 469p following the group's statement.
- [14]
Asos warned: "Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
- [15]
Last year, IT workers at Marks and Spencer were tricked by hackers who gained access to the retailer's systems.
- [16]
A fall of 13% followed by a rise of 4% leaves the shares about 9.5% below their starting level.
- [17]
A fall of 10% followed by a rise of 4% leaves the shares about 6.4% below their starting level.
- [18]
Asos shares fell more than 13 per cent after the hackers' notification.
- [19]
The notification sent Asos shares diving by about 10%.
- [20]
The sell-off cast doubt on Asos's ability to continue its turnaround plan.
Sources
2 independent publishers whose own reporting we read for this story.
- cityam.comAsos hackers duped employee in data breach
1 article · October 8, 2026
- theguardian.comAsos says customer data accessed by hacker posing as trusted contact
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Social Engineering and Voice PhishingFollow
- Retail cybersecurityFollow
- Data Breach DisclosureFollow