Reported by 1 source

The short version

  • Hackers obtained names, addresses, and browsing histories from Asos users, contradicting earlier claims that only basic contact info was at risk.
  • The intrusion occurred after criminals impersonated a trusted contact to steal employee login credentials for a third-party data service.
  • Customers are advised to remain vigilant against targeted scams while the retailer investigates the full scope of the compromise.

Online fashion retailer Asos has acknowledged that cybercriminals possess detailed personal profiles of potentially millions of its customers, significantly expanding the known impact of a recent security breach. The update follows revelations that the stolen data extends far beyond the basic contact information the company initially reported as compromised. This escalation in severity raises immediate concerns about the potential for highly targeted social engineering attacks against consumers who trust the brand.

The incident first drew global attention when unauthorized actors hijacked Asos’s application system to broadcast a pop-up notification to users. At that time, the retailer informed shareholders and customers via email that an unapproved third party had accessed basic personal information, including names and contact details. However, subsequent evidence suggests the intrusion penetrated deeper into customer records than originally disclosed.

News Journal

Cybercriminals identified themselves as Xuanyewen contacted news organizations to share samples of the stolen data, demonstrating the true extent of the leak. The exposed files contain not only names, addresses, phone numbers, and email addresses but also specific search terms entered by users on the website. Visible queries include phrases such as reclaimed vintage, glamorous wide fit, and Asos petite, offering a granular view of individual shopping habits and preferences.

This level of detail transforms the threat landscape for affected users. With access to both personal identifiers and behavioral data, scammers can craft convincing phishing emails or phone calls that appear legitimate. The risk of impersonation scams has increased substantially, as attackers can leverage specific purchase interests to build credibility with their targets. Asos has warned customers to remain cautious of unexpected communications claiming to originate from the company.

The mechanism behind the breach involved social engineering rather than a direct technical exploit of Asos’s core infrastructure. The retailer explained that hackers gained entry by impersonating a trusted contact to obtain login credentials for an employee account. These credentials provided access to an unnamed service, which allowed the attackers to download customer data. This method highlights the persistent vulnerability of human factors in cybersecurity defenses.

The criminals claimed they compromised a Snowflake instance, a popular cloud-based data storage and analysis platform. They further alleged using Simon AI, a platform built natively on top of Snowflake, to facilitate access to the information. While Snowflake previously stated its platform had not been breached, the incident underscores the risks associated with third-party integrations and complex data ecosystems. Simon AI has been contacted for comment regarding these allegations.

Despite the severity of the personal data exposure, Asos maintains that no bank details or passwords were accessed during the intrusion. The company emphasized that it will never request sensitive information such as security codes or payment details through unsolicited messages. Customers are not currently required to take specific action, though the retailer has implemented additional steps to strengthen security controls and is continuing its investigation.

Cybersecurity experts recommend proactive measures regardless of official guidance. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, advised users to change passwords as a precaution and remain alert for suspicious activity. He warned that scammers are likely to reference the attack directly, using stolen personal details to create a sense of urgency, such as threatening account lockouts within twenty-four hours. Vigilance remains the primary defense against these evolving threats.

Asos has assured users that its website and app remain safe to use, reiterating its commitment to protecting customer trust. The company stated it will contact individuals directly if further information or support becomes necessary. As the investigation continues, the full scale of the breach remains unclear, leaving many questions about the total number of affected accounts and the long-term implications for data privacy in the retail sector.

Sources behind this briefing

Go to the original reporting

  • BBC Technology↗Asos hackers took more personal details than first revealed, BBC finds