Language Settings
Select Website Language

GDPR Compliance

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you accept our use of cookies, Privacy Policy, and Terms of Service.

ASOS Confirms Customer Data Breach After Employee Account Compromise

1 hour ago

3

0

ASOS says a cyberattack exposed some customer names and contact details after an attacker obtained employee credentials through impersonation.

By News National Editorial Team

LONDON, October 12, 2026: British online fashion retailer ASOS has confirmed a cybersecurity incident in which an unauthorised person accessed some customers' personal information after obtaining login credentials for an employee account through impersonation.

In a customer communication reported by Reuters on October 8, ASOS said its initial investigation found that names, contact details and certain non-personal account-related information had been accessed. The retailer said payment-card information and account passwords were not exposed, according to its findings at that stage. 

How the incident happened

ASOS said an unauthorised person impersonated a trusted contact to obtain an employee's login credentials. The credentials were then used to access information on certain third-party platforms used by the company.

The method is known as social engineering. Instead of relying exclusively on a technical vulnerability, an attacker manipulates a person into disclosing information or taking an action that compromises security.

Once an employee account is compromised, the level of access available to that account can determine how much information an attacker can reach. Connections to external services may increase the risk if permissions are broader than necessary or if access is not monitored effectively.

ASOS said it immediately locked down the affected platforms. The company also said its website and app remained safe to use throughout the incident and continued to be safe to use after the breach was discovered. It was cooperating with law-enforcement and regulatory authorities, Reuters reported.

What information was exposed?

The retailer's initial investigation identified customer names, contact details and certain non-personal account-related information as exposed. ASOS said payment-card information and account passwords were not compromised.

That distinction is important. There is no basis in the reported company statement to claim that payment-card details or passwords were stolen in this incident.

However, contact details can still be valuable to criminals. Information about a customer's relationship with a retailer may help attackers create convincing phishing emails, text messages or phone calls that imitate customer support or delivery services.

Customers should be cautious of unexpected messages asking them to click a link, disclose a verification code, confirm account details or make an additional payment. If a message appears suspicious, customers should visit the retailer's official website or app directly rather than using links supplied in the message.

The company had not publicly established in the reporting available for this article that the exposed information had been used for further fraud. Any claims about subsequent misuse or the precise number of affected customers should be based on later company or regulator updates.

Why employee-account security matters

Employee accounts can provide access to customer-service systems, marketing platforms, analytics tools and other third-party services. If an attacker gains control of an account, the resulting exposure may extend beyond the employee's primary workplace computer.

Businesses should use strong authentication, including phishing-resistant multi-factor authentication where possible. Employees should be trained to verify unusual requests through a separate communication channel, especially when a message asks for credentials or access to sensitive systems.

Companies should also limit employee permissions, monitor unusual login behaviour and review third-party integrations regularly. Access to external platforms should be revoked promptly when credentials may have been compromised.

Protecting customers and responding to breaches

Retailers should have a clear process for investigating suspected incidents, securing affected accounts, preserving evidence and notifying customers or regulators where required. They should also review the scope of any exposure and communicate confirmed findings without overstating what is known.

For customers, the most practical response is to remain alert to suspicious messages and never share one-time passwords or account credentials with someone who contacts them unexpectedly. Customers should use official channels to check whether a request is genuine.

A wider warning for online retailers

The ASOS incident demonstrates that a company can face a data-security problem through an employee account and a connected external service, even when its public-facing shopping platform remains available.

Protecting customer information therefore requires more than securing a website. Employee authentication, third-party permissions, monitoring and incident-response procedures all play a role.

The retailer's initial findings offer a clear lesson for online businesses: impersonation can lead to credential theft, and compromised credentials can expose customer information. Strong identity controls and carefully managed access to external platforms can help reduce the risk of similar incidents.

Source:

Click here to Read More
Previous Article
FBI Data Breach Exposes Sensitive Employee Records After Patch Failure

Related Cyber Security Updates:

Are you sure? You want to delete this comment..! Remove Cancel

Comments (0)

    Leave a comment