← Back to the feed

Asos confirms customer details and app searches exposed in cyber attack

The Guardian ·

Asos says an unidentified third party accessed millions of customers’ personal information and recent app search histories in a cyber attack. The incident matters because exposed contact details and searches could enable targeted scams, while the loss of customer trust may hinder the retailer’s efforts to rebuild sales.

The attackers reportedly impersonated a trusted contact to obtain an Asos employee’s login credentials, then used them to access a database held by a third-party service provider. Names, delivery and email addresses, phone numbers and some account-related information were accessed, but Asos says passwords and payment card details were not. The retailer says it locked down the affected platforms, is working with authorities and advises customers to be wary of unexpected calls or messages.

  • Millions of customers’ details and recent searches were accessed.
  • Asos says passwords and payment card details were not affected.
  • The attackers reportedly gained access by impersonating a trusted contact.

New here? Start with this

Asos, a major online fashion retailer, has disclosed that millions of its customers' personal information was accessed by hackers in a cyber attack. The attackers also viewed recent searches customers made using the Asos app, which revealed their shopping interests and habits.

The exposed data includes names, delivery addresses, email addresses and phone numbers. Whilst passwords and payment card details remained secure, the leaked contact information could be used to target customers with convincing scams or unwanted approaches. The breach is significant because it could undermine customer confidence in the retailer at a time when Asos is working to restore trust and rebuild sales.

The attackers gained access by impersonating a trusted contact to trick an Asos employee into revealing their login details. They then used these details to access a database held by a third-party service provider. Asos has since secured the affected systems and is working with law enforcement, whilst advising customers to be cautious of unexpected calls or messages.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Asos failed to implement sufficient security safeguards to protect millions of customers' personal data. Large retailers handling sensitive customer information should enforce mandatory multi-factor authentication for employee access to critical systems, which would have prevented the breach even with compromised credentials. The company bears responsibility for this security gap, and the incident reflects inadequate protective measures in an era when such breaches are increasingly common and preventable.

The case against

Sophisticated social engineering attacks deliberately exploit human psychology rather than technical vulnerabilities, making them exceptionally difficult to prevent without severely compromising operational efficiency. Asos's response demonstrates appropriate crisis management: rapidly containing the breach, securing systems, notifying customers promptly, and cooperating with law enforcement. The fact that payment details and passwords remained protected indicates security layering functioned as designed, and attributing this incident solely to corporate negligence disregards the reality that no system can be entirely impenetrable against sophisticated, human-directed attacks.

Business Culture Cybersecurity Fashion Software Technology

Read the full article at the source →

Originally published by The Guardian as “Asos customers’ names, search histories and contact details accessed in hack, says retailer”.