Skip to content

LeadershipReports disagree2 publishers3 min readPublished

Asos traces its data breach to one employee fooled by a fake trusted contact

Asos said hackers obtained an employee's login by posing as a trusted contact, then reached customer names and contact details on third-party platforms. The shares fell on the hackers' app alert two days before Asos explained it. For a board, that puts staff checks and disclosure speed inside the same risk.

The Board Room · Leadership desk

How we use AISend a correction

Illustration accompanying Asos traces its data breach to one employee fooled by a fake trusted contact
Generated illustration

What happened

  • Hackers announced the breach on Tuesday through a push notification on Asos's own app, linking to a Telegram channel run by a group calling itself Xuanye Group.
  • Asos said it locked down the affected platforms and referred the incident to law enforcement and regulatory authorities.
  • Shares fell more than 13% by City AM's count and about 10% by the Guardian's on the day the hackers' alert went out.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure A vendor can report its platform intact while a customer's account on it is emptied with valid credentials. The reach of each staff login inside outside tools sets how much one con exposes.
  • cost Shareholders took most of the loss before Asos had said anything, and confirming that no payment data was taken won back only part of it.
  • decision An attacker who controls a company's own customer channel sets the disclosure clock. Boards have to decide in advance how fast a factual holding statement can go out.

The con worked on one person, and the damage grew with what that person's login could open. Asos described the sequence in its Thursday statement: "We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos." [1] One employee account led into more than one outside platform.

The hackers' own notice named one of those platforms. It read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." [7] A Snowflake spokesperson said the company found "no compromise" of its platform [8]. Both statements can be true. A vendor's systems can be intact while a customer's account on them is entered with valid credentials, and Asos's statement refers only to "certain third-party platforms" [1]. City AM describes Snowflake as a cloud platform used to process data such as clothing sizes and body measurements that also lets users send notifications to clients' phones [9]. If the hackers' claim is accurate, the login that exposed customer data also gave them Asos's channel to its customers' phones [3].

On this record, the first failure was human [1]. Asos's statements do not say whether the stolen credentials were protected by a second authentication factor, or why one employee's access extended to customer contact data and a notification tool [1]. In my view a person and an access design failed together here: the impersonation produced the credentials, and the permissions let them reach several platforms. City AM noted that IT workers at Marks and Spencer were tricked by hackers who got into that retailer's systems last year [15].

The share price reacted to the hackers' announcement, before anyone outside knew how they got in. Asos made its first announcement on Thursday morning [5], after what the Guardian called a "detailed, 48-hour investigation" [6]. City AM put the fall at more than 13% [18]. The Guardian put it at about 10% [19]. After the statement the shares rose 4% to 469p [13]. Taken back to back, with no other moves between them, a 13% fall and a 4% rise leave the stock about 9.5% below where it started [16]; on the Guardian's figure, about 6.4% below [17]. City AM wrote that the sell-off cast doubt on the company's ability to continue its turnaround plan [20].

The trade-off for a board is speed of disclosure against accuracy. Here the attackers set the timing, by publishing through Asos's own app to thousands of users, according to the Guardian [4]. When Asos did speak, it was specific: names and contact details accessed, no payment information or passwords [2], platforms locked down and the case referred to law enforcement and regulators [10]. It also warned customers against the same technique that worked on its employee: "Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call." [14]

This quarter's decision for an operator is how quickly a factual holding statement can go out once an attacker goes public, and who verifies a "trusted contact" before credentials change hands [1]. Next quarter's consequence arrives when Asos's investigation ends and it contacts customers directly "where we believe additional information, support or action may be required" [11].

What to watch

  • Whether Asos names the third-party platforms involved and says whether the stolen login was protected by a second authentication factor.
  • How many customers Asos contacts directly when its investigation ends, and any action from the regulators it notified.
  • Whether the Xuanye Group publishes data once its stated "designated period" runs out.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives70
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Asos said: "We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos."

    ReportedSupportedSource: Asos statement to customers, reported by City AM and the Guardian2 sources— create a free account to open themView cited source
  2. [2]

    Asos confirmed basic personal information of customers, including names and contact details, was accessed; payment card details and passwords were not accessed.

    ReportedSupportedSource: Asos, via the Guardian2 sources— create a free account to open themView cited source
  3. [3]

    On Tuesday hackers published a push notification on the Asos app claiming to have hacked the company and threatening a data leak; it linked to a Telegram channel where a user named 'Xuanye Group' posted.

Sources

2 independent publishers whose own reporting we read for this story.

  1. cityam.com

    1 article · October 8, 2026

    Asos hackers duped employee in data breach
  2. theguardian.com

    1 article · October 8, 2026

    Asos says customer data accessed by hacker posing as trusted contact

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories