Asos Data Breach Exposes Millions of Customer Records Including Search Histories
Developing story first seen 2 hours ago
Asos has now confirmed that hackers accessed customer search histories alongside personal data—far more than initially disclosed. The fashion retailer previously said only "basic contact details" were compromised, but cyber criminals who contacted the BBC showed they possessed names, addresses, phone numbers, emails, customer numbers and search terms like "plus size", "glamorous wide fit" and "reclaimed vintage". No passwords or bank details were taken, but the stolen information gives scammers ammunition to craft convincing phishing attacks using customers' shopping behaviour and personal details.
How the breach occurred has also emerged: hackers impersonated a trusted contact to obtain an Asos employee's login credentials, then used that access to download customer data from a Snowflake-based platform called Simon AI. The cyber criminal group calling themselves Xuanyewen sent the initial pop-up notification to millions on Tuesday, then provided evidence of their access to the BBC, forcing the company to acknowledge the true scope. Cybersecurity experts have warned users to be highly suspicious of any unsolicited messages claiming to be from Asos and asking them to change passwords, as scammers will likely exploit the breach to impersonate the company.
- Asos confirms hackers accessed search histories and personal data of millions
- Cyber criminals proved the breach went far beyond initial company disclosures
- Experts warn of phishing scams using stolen personal details and shopping behaviour
New here? Start with this
Asos is one of the world's largest online fashion retailers, serving millions of customers globally who buy clothes, shoes and accessories through its website and app. A cyber attack has compromised personal information held by the company, affecting a significant portion of its customer base and raising concerns about data security in the retail sector.
The breach exposed more than basic contact details, including customers' detailed shopping search histories that reveal their style preferences and interests. This information was more extensive than Asos initially acknowledged, only becoming fully apparent when a cyber criminal group shared evidence of the incident with BBC journalists.
The exposure of personal data combined with shopping behaviour records creates risks for customers, who could face targeted fraud attempts or unwanted contact. It also damages trust in the retailer's ability to protect customer information, a critical concern for any company operating online.
Full account
Online fashion outlet Asos has revealed that a significant security incident has resulted in unauthorised access to personal information held by millions of customers. The breach emerged into public consciousness on Tuesday when an alert was transmitted through the retail platform's mobile application, though the company's subsequent investigation uncovered a wider collection of compromised data than initially conveyed.
According to Asos, the intrusion occurred through a social engineering attack targeting staff members. The attackers fraudulently represented themselves as a trusted party to extract authentication credentials from an employee, thereby gaining unauthorised entry to connected third-party services utilised by the business.
The data obtained by the unauthorised actors encompasses customer identities, geographical addresses, communication numbers and electronic mail addresses. Of particular concern is the capture of browsing records documenting queries customers have typed into the platform, with captured search terms including 'glamorous wide fit' and 'Asos petite'. Financial transaction details and user account passwords were not compromised by the intrusion.
Security specialists have cautioned that the combination of verified personal information alongside documented search behaviour creates an ideal foundation for sophisticated deception campaigns targeting customers. Asos has advised its customer base to remain vigilant against unsolicited communications purporting to originate from the retailer, emphasising that it will never request sensitive data through unexpected contact.
Asos has stated that the security of its digital platforms remains sound and that customers may continue shopping without taking immediate action. The retailer has committed to offering individual support to affected customers as its investigation advances. The company is collaborating with external cybersecurity specialists and relevant regulatory authorities to establish the complete scope of the incident.
Where outlets differ
One source identifies the threat actors as 'Xuanye Group' whilst the other refers to them as 'Xuanyewen'
One source details the alleged use of Snowflake and Simon AI platforms in the compromise, whilst the other omits these technical specifics
One source emphasises the BBC's investigative contribution in revealing the true extent of the breach, whereas the other concentrates on Asos's independent response
One source incorporates market analysis assessing potential business repercussions, which does not feature in the other
Coverage
- The Guardian — Asos confirms customer details and app searches exposed in cyber attack
- BBC Technology — Asos says hackers accessed millions of customer profiles in data breach