Asos says hackers accessed millions of customer profiles in data breach
Developing story first seen 2 hours ago
Following contact from the BBC, Asos has now disclosed that hackers accessed detailed customer profiles extending far beyond the "basic contact details" initially reported, including search histories with specific queries like "reclaimed vintage" and "glamorous wide fit." The cyber criminal group Xuanyewen contacted the BBC with evidence of the broader breach, prompting the retailer to significantly expand its disclosure to customers. This revelation substantially increases the risk to millions of users, as scammers now possess personal information enabling targeted phishing attacks and convincing impersonation schemes.
The hackers compromised an employee account after impersonating a trusted contact to obtain login credentials, then used those to access Asos's customer data stored on Snowflake through the Simon AI platform. Whilst passwords and bank details remain uncompromised, security experts warn customers to expect sophisticated scams mentioning the attack and using personal details to appear genuine, often threatening account lockouts to create urgency. Asos advises customers not to provide sensitive information via unsolicited messages and recommends changing passwords as a precaution, though experts stress passwords were not stolen.
- BBC investigation revealed hackers stole detailed customer search histories, not just basic contact data
- Scammers now have personal information to craft targeted phishing and impersonation attacks
- Security experts warn of fake urgent messages threatening account lockouts
New here? Start with this
Asos is one of the UK's largest online fashion retailers, with millions of customers shopping for clothing and accessories. The company has disclosed that hackers gained access to detailed customer profiles following a significant data breach.
The stolen data includes names, addresses, phone numbers, email addresses, account numbers and search history, though passwords and bank details remained secure. Hackers compromised an Asos employee's login credentials by impersonating a trusted contact, then used that access to reach the company's data storage system.
With personal information now in the hands of cyber criminals, customers face an increased risk of scams where fraudsters impersonate Asos or use their details to trick them into revealing more sensitive information. Asos has advised customers to be cautious of unsolicited messages and confirmed its platform remains safe to use.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Whilst the breach is undoubtedly unwelcome, the company's now comprehensive disclosure represents responsible incident management. Critically, the most sensitive data—passwords and banking information—remained protected through separate security measures, substantially mitigating the risk of direct financial harm. The company has appropriately notified customers and maintained that the platform remains safe for continued use, acknowledging that social engineering represents a human vulnerability rather than evidence of systematic platform failure.
The case against
The initial understatement of the breach, only corrected after media intervention, demonstrates insufficient transparency and raises accountability concerns. The exposure of millions of detailed customer profiles—including addresses, phone numbers and search histories—provides cybercriminals with precisely the information required for sophisticated impersonation and phishing attacks. The security failure that permitted a compromised employee account to access critical data systems represents a fundamental breakdown in access controls that should concern customers about the adequacy of their personal data protection.
Full account
On Tuesday this week, fashion retailer Asos was subjected to a significant data breach when customers received an unusual notification through the company's app claiming the firm had been "hacked". The notification included a link to a Telegram messaging channel operated by the attackers, generating considerable alarm amongst millions of users. Asos initially disclosed that only "basic personal information" had been compromised, specifically naming and contact details. However, subsequent investigation and communications from the perpetrators revealed the breach extended considerably beyond these preliminary assertions, affecting customer data far more extensively than first acknowledged.
The breach occurred after an unauthorised party successfully impersonated a trusted contact to obtain login credentials belonging to an Asos employee. These credentials were subsequently utilised to access information stored on third-party platforms used by the retailer, with compromised systems immediately secured once the intrusion was discovered. The attackers, identifying themselves variously as Xuanyewen or the Xuanye Group, claimed in their notification to have "fully compromised the Snowflake instance", referring to Asos's cloud-based data storage system. This access method represented considerably more sophistication than conventional phishing campaigns, indicating a significant security failure at the employee authentication level.
The expanded scope of compromised data includes customer names, addresses, telephone numbers, email addresses and account numbers. Additionally, records of search queries made by customers on the Asos platform were obtained, potentially revealing shopping preferences exploitable in targeted phishing campaigns or impersonation scams. The company confirmed that payment card details and passwords remained uncompromised, limiting certain immediate financial risks. However, the combination of personal information and browsing history enables sophisticated social engineering attacks, prompting Asos to advise customers to remain sceptical of unsolicited communications purporting to originate from the company.
Asos emphasised that it would never request passwords, security codes or payment information through unexpected messages or calls. The company stated it would contact affected customers directly where additional support was deemed necessary following investigation completion. The incident generated shareholder concern, with Asos's stock price declining between nine and ten per cent following breach disclosure. The attackers reportedly demanded ransom payment in exchange for data deletion, issuing an ultimatum of approximately two weeks for engagement, accompanied by threats to publicly release customer information if demands were not met.
Where outlets differ
SOURCE 1 emphasises phishing risk and provides specific customer search term examples, whilst SOURCE 3 concentrates on ransom demands and the two-week engagement deadline
SOURCE 2 notes cybersecurity experts were unfamiliar with the named group, a detail absent from other reports
Stock decline reporting varies between 9 and 10 per cent across sources
SOURCE 3 characterises the attack as 'unusually brazen', whilst SOURCE 1 emphasises technical sophistication and social engineering risks
The attacking group is named 'Xuanyewen' in SOURCE 1 but 'Xuanye Group' in SOURCES 2 and 3
More coverage
- The Guardian — Asos says customer data accessed by hacker posing as trusted contact
- Daily Mail — Asos hackers 'in possession of detailed profiles of potentially millions of customers'
Read the full article at the source →
Originally published by BBC Technology as “Asos warns customers about full extent of data breach after BBC contacted by hackers”.