Qz ASOS Data Breach: Employee Credentials Compromised by Xuanye Group
Article Content
- •The Xuanye Group exploited social engineering to gain employee login credentials.
- •Customer personal information was accessed, but payment details remain secure.
- •Hackers are threatening customers directly, raising concerns about further data exposure.
ASOS confirmed a data breach on October 6, 2026, where hackers, identified as the Xuanye Group, accessed customer data by tricking an employee into revealing their login credentials. The attackers utilized these credentials to infiltrate third-party platforms used by ASOS, allowing them to send unauthorized push notifications to customers. The breach reportedly exposed personal information, including names, addresses, and email addresses, but ASOS stated that payment information was not compromised. Following the breach, hackers began sending threatening messages to customers, demanding payment to avoid data leaks. The U.K. Information Commissioner's Office has been notified and is assessing the situation. ASOS shares initially fell but later rose as the scope of the breach appeared narrower than feared. The company is working with cybersecurity specialists to investigate the incident and has secured access to affected platforms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track Xuanye Group and ASOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What type of information was compromised?
How did the attackers gain access?
What should affected customers do?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…