ASOS Plc said a recent data breach occurred when an “unauthorized party” impersonated a trusted contact to dupe an employee at the online fashion retailer into handing over log-in details for their work account.
The hackers, calling themselves the Xuanye Group, then used those credentials to access information on certain third-party platforms used by ASOS, the UK company said Thursday in an update to customers.
The affected platforms have been locked down and a full investigation has been launched, ASOS said, adding that the website and app remain safe to use. The hackers have access to some personal information, including names and contact details, but no payment card information or account passwords were accessed, it said.
Shares of ASOS rose as much as 5.3% in London on the news that the attack was not as widespread as initially feared.
Earlier this week, ASOS shares plunged after users of its shopping app received a push notification threatening to leak data. The hackers claimed in the message that they had also compromised ASOS’s Snowflake system, a cloud-based platform used to store large repositories of data. At the time they did not provide any evidence to support their claims, and a spokesperson for Snowflake Inc. later said its platform had not been breached.
Read more: ASOS Says Cyberattack May Have Compromised Customer Data
There have been no further updates posted by the hackers since Tuesday. The UK Information Commissioner’s Office said it had been notified of a breach by ASOS and is assessing the situation.
British retailers have suffered a number of cyberattacks in the past year, with sophisticated cybercrime groups like ShinyHunters targeting large organizations to steal data. Marks & Spencer Group Plc endured months of disruption after an attack last year forced it to pause online clothing and home orders.
Xuanye Group was first active on Telegram in early September under the username @JohnCzwartacki, according to Anastasia Tikhonova, global head of threat research at the cybersecurity company Group-IB. She said the group later changed its name to @NFTmoonstock before renaming itself again as @xuanyegroup on Oct. 6, the day it claimed responsibility for the intrusion at ASOS.
Xuanye Group’s Telegram account had not previously been associated with any cyberattacks and instead had been active trading items related to online gaming, Tikhonova said.
Photograph: ASOS branding; photo credit: Nathan Stirk/Getty Images
Topics Cyber
Was this article valuable?
Here are more articles you may enjoy.

McKinsey Rebukes Partner Who Questioned Challenges Facing Women CEOs
Zurich Insurance Completes Acquisition of Beazley, Names New Beazley CEO
Viewpoint: State Socialism Meets Insurance
McDonald’s Hit With Class Action Alleging AI-Powered Menu Price-Fixing 

