Asos has told customers that hackers are holding detailed profiles of potentially millions of users of the online store, after cyber criminals contacted BBC News and said this week’s breach went further than the “basic contact details” the retailer had previously said might have been accessed.
The data now in the hands of criminals includes names, addresses, phone numbers, emails, customer numbers and dates of birth, the company told users.
The stolen material also takes in the searches shoppers have carried out on the website, with terms such as “reclaimed vintage”, “glamorous wide fit” and “Asos petite” appearing in the data, according to the BBC.
One customer said the extent of the personal information now held by the hackers was “very unsettling”. Harriet, who told the BBC she has been an Asos shopper since 2019 — another detail the criminals now know — said she was particularly concerned about how the data could be used in future.
“What I find particularly worrying is the possibility that stolen data can be used as a tool for for future attacks, meaning the impact of a breach could extend well beyond the initial incident,” she said.

With the stolen information, scammers may be able to send convincing phishing emails or make persuasive phone calls, raising the risk to individuals. Customers are being warned about potential impersonation scams.
In its email to customers, Asos confirmed that data profiles had been taken but said no bank details or passwords were accessed.
“Please remain cautious of unexpected messages or calls claiming to be from Asos,” it said. “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
The company did not respond to questions about the scale of the breach.
App notification made global headlines
The high-profile hack made global headlines on Tuesday, when cyber criminals used Asos’s own app system to push a pop-up notification to potentially millions of people.

Later that day, the firm confirmed to shareholders via the London Stock Exchange that the pop-up had been sent by an “unauthorised third party” and that “basic personal information including name and contact details may have been accessed”. An email to customers followed with similar wording.
On Wednesday evening, the cyber criminals responsible contacted the BBC and shared a sample of the stolen data, which demonstrated the true extent of the hack. The BBC held off publishing this article so that Asos could contact its customers first.
Asos said it is still investigating the data breach and that it would “contact customers directly where we believe additional information, support or action may be required”.
The UK fashion site explained to customers that hackers gained access to an Asos employee account by “impersonating a trusted contact to obtain log in credentials”. Using that log in to an unnamed service, the hackers were able to download the customer data.
Hackers claim they compromised a Snowflake instance
In the pop-up notification sent to customers by the hackers, they claimed they had “compromised the Snowflake instance”. Snowflake is a popular data storage and analysis company whose customers have been breached in the past as a result of unauthorised log ins.

The cyber criminals, who call themselves Xuanyewen, told the BBC they used a platform built natively on top of Snowflake, called Simon AI, to gain access to the data. Simon AI has been contacted for comment, and Snowflake has previously said its platform had not been breached.
Passwords not affected, but experts urge caution
Asos said customers are not being asked to take any action. However, cyber security experts have advised users to change their passwords as a precaution and to watch for suspicious activity.
“Passwords have not been stolen, so be highly suspicious of any unsolicited text or email asking you to change or share yours,” said Trevor Dearing, Senior Director of Critical Infrastructure at Illumio.
“Expect scammers to mention the attack, use your personal details to seem genuine, and create urgency, such as threatening to lock your account within 24 hours.”
Asos said its website and app are safe to use and that “we know our customers trust us with their information”.
“We take that responsibility seriously and have already taken additional steps to further strengthen security controls,” it said.








COMMENTS