Asos Warns Customers of Full Data Breach After BBC Contact
Key Takeaways
- Asos confirmed cyber criminals hold detailed user profiles including names, addresses, and search history.
- The true extent of the breach was revealed after hackers contacted the BBC with stolen data samples.
- No bank details or passwords were stolen, but the risk of targeted phishing attacks has increased.
- Hackers gained access by impersonating a trusted contact to steal an employee's login credentials.
Online fashion retailer Asos has issued an urgent warning to its customer base, revealing that hackers have successfully gained possession of detailed user profiles potentially affecting millions of accounts. This major security update came to light after BBC News contacted the retailer, disclosing that cyber criminals had reached out directly to share samples of the stolen data. The evidence provided to the BBC proved that the incident extended significantly further than the basic contact details Asos had previously acknowledged to the public and its shareholders.
The compromised datasets now in the hands of unauthorized actors include full names, physical addresses, telephone numbers, email addresses, and unique customer identification numbers. Furthermore, the breach exposes intimate details regarding how users interact with the platform, including specific search terms entered on the website such as reclaimed vintage clothing, glamorous wide fit options, and Asos petite ranges. Cybersecurity analysts point out that this granular level of information provides malicious actors with the tools necessary to craft highly convincing and potent phishing attack emails or deceptive phone calls, thereby elevating the overall risk profile for affected individuals.
In official communications sent to its customers, Asos confirmed that user data profiles were indeed exfiltrated during the incident, while reassuring users that financial details such as bank accounts and credit card numbers, as well as account passwords, remained secure and untouched. The company explicitly urged its consumer base to remain exceptionally cautious regarding unexpected messages or unsolicited phone calls purporting to originate from Asos. The retailer reiterated its standard security policy, emphasizing that it will never request passwords, security authentication codes, or payment information through unsolicited channels.
The high-profile security breach first captured global headlines when malicious actors managed to exploit Asos's own mobile application infrastructure. The hackers used the internal notification system to broadcast an unauthorized pop-up message directly to potentially millions of smartphone users. Later that same day, the retail firm formally confirmed to shareholders via the London Stock Exchange that the intrusion was perpetrated by an unauthorized third party, initially estimating that only basic personal information had been accessed. Subsequent investigations driven by the hackers contacting the BBC revealed the true and extensive nature of the data exposure.
Regarding the mechanics of the attack, Asos stated that its ongoing investigation indicates the hackers managed to gain unauthorized access to an internal employee account. The perpetrators reportedly achieved this by successfully impersonating a trusted contact to fraudulently acquire administrative login credentials. Utilizing this compromised access to an unnamed third-party service, the malicious actors successfully downloaded the vast repository of customer information.
During their communications with the public via the rogue app notification, the hackers claimed responsibility under the name Xuanyewen and asserted that they had compromised a Snowflake data storage instance. They further claimed to have utilized Simon AI, a platform built natively on top of Snowflake, to facilitate the data extraction. Both Snowflake and Simon AI have faced scrutiny regarding these claims, although previous statements from storage providers indicated their core infrastructures remained uncompromised. Asos has noted that customers do not need to take immediate administrative action, though independent cybersecurity experts strongly advise users to update their passwords as a precautionary measure and remain vigilant against suspicious activity.
Recommended for you
Tools and services we trust to boost productivity and content workflows.
Browse picks