← Back to the feed

Asos says hackers accessed millions of customer profiles in data breach

Developing story first seen 1 hour ago

BBC Technology ·

Following contact from the BBC, Asos has now disclosed that hackers accessed detailed customer profiles extending far beyond the "basic contact details" initially reported, including search histories with specific queries like "reclaimed vintage" and "glamorous wide fit." The cyber criminal group Xuanyewen contacted the BBC with evidence of the broader breach, prompting the retailer to significantly expand its disclosure to customers. This revelation substantially increases the risk to millions of users, as scammers now possess personal information enabling targeted phishing attacks and convincing impersonation schemes.

The hackers compromised an employee account after impersonating a trusted contact to obtain login credentials, then used those to access Asos's customer data stored on Snowflake through the Simon AI platform. Whilst passwords and bank details remain uncompromised, security experts warn customers to expect sophisticated scams mentioning the attack and using personal details to appear genuine, often threatening account lockouts to create urgency. Asos advises customers not to provide sensitive information via unsolicited messages and recommends changing passwords as a precaution, though experts stress passwords were not stolen.

  • BBC investigation revealed hackers stole detailed customer search histories, not just basic contact data
  • Scammers now have personal information to craft targeted phishing and impersonation attacks
  • Security experts warn of fake urgent messages threatening account lockouts

New here? Start with this

Asos is one of the UK's largest online fashion retailers, with millions of customers shopping for clothing and accessories. The company has disclosed that hackers gained access to detailed customer profiles following a significant data breach.

The stolen data includes names, addresses, phone numbers, email addresses, account numbers and search history, though passwords and bank details remained secure. Hackers compromised an Asos employee's login credentials by impersonating a trusted contact, then used that access to reach the company's data storage system.

With personal information now in the hands of cyber criminals, customers face an increased risk of scams where fraudsters impersonate Asos or use their details to trick them into revealing more sensitive information. Asos has advised customers to be cautious of unsolicited messages and confirmed its platform remains safe to use.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Whilst the breach is undoubtedly unwelcome, the company's now comprehensive disclosure represents responsible incident management. Critically, the most sensitive data—passwords and banking information—remained protected through separate security measures, substantially mitigating the risk of direct financial harm. The company has appropriately notified customers and maintained that the platform remains safe for continued use, acknowledging that social engineering represents a human vulnerability rather than evidence of systematic platform failure.

The case against

The initial understatement of the breach, only corrected after media intervention, demonstrates insufficient transparency and raises accountability concerns. The exposure of millions of detailed customer profiles—including addresses, phone numbers and search histories—provides cybercriminals with precisely the information required for sophisticated impersonation and phishing attacks. The security failure that permitted a compromised employee account to access critical data systems represents a fundamental breakdown in access controls that should concern customers about the adequacy of their personal data protection.

More coverage

Cybersecurity Technology

Read the full article at the source →

Originally published by BBC Technology as “Asos warns customers about full extent of data breach after BBC contacted by hackers”.