An unknown group calling itself the Xuanye Group gained access to personal data of millions of Asos customers by impersonating a trusted contact to steal login credentials from a single employee. The compromised credentials were then used to access third-party platforms used by the retailer. Names, contact details, and unspecified "non-personal account related information" were exposed. Payment card data and passwords were not accessed. The breach was surfaced not by Asos but by the attackers themselves, who pushed a notification titled "Asos hacked" to thousands of app users on Tuesday, directing them to a Telegram channel. The notification triggered a roughly 10% drop in Asos shares — a self-inflicted market event where the hackers, not the company, controlled disclosure timing. Asos completed a 48-hour investigation before confirming the breach on Thursday. The attack vector is textbook social engineering: credential phishing through impersonation of a trusted contact. No zero-day exploit, no sophisticated malware — just a convincing impersonation and one compromised account. The real vulnerability was organizational, not technical. Asos had a single employee account with enough access to reach customer data across multiple third-party platforms, which means either excessive privilege or insufficient segmentation. Asos locked down the affected platforms and says it has "strengthened security controls," though specifics were not provided. The company is working with law enforcement and regulatory authorities. It warned customers to be cautious of unsolicited messages or calls claiming to be from Asos — effectively telling millions of people whose contact details were just stolen to watch out for the phishing campaigns those stolen details will enable. The Xuanye Group is unknown to cyber experts, who speculate the push notification stunt may have been a bid for attention rather than a prelude to monetization. That theory is generous. Stolen contact details for millions of customers have direct value on dark-web markets, and the Telegram channel's reassurance that "payment information is not affected" reads more like reputation management for future operations than altruism. The broader pattern is familiar: a major retailer with millions of customer records secured behind the weakest link in any system — a human being susceptible to a well-crafted impersonation. Asos joins a long list of companies where the breach cost is socialized across millions of customers who now face years of elevated phishing risk, while the company absorbs a short-term share price hit and moves on. The 10% share drop, driven by the hackers' own push notification, is the most structurally interesting detail. The attackers weaponized Asos's own infrastructure to punish the company in the market, demonstrating a level of operational creativity that goes beyond data theft. Whether this was leverage for ransom, a demonstration of capability, or pure spectacle, it shows how breach disclosure itself has become a vector of harm.