Skip to content
Search

Latest Stories

Submit Guest Post

ASOS hack exposed what millions of customers were searching for. Here’s what we know

The fashion retailer says names, contact details and other customer information were accessed after hackers impersonated a trusted contact to obtain an employee’s login credentials

Asos hacked

ASOS says hackers accessed customer information but not passwords or payment card details

iStock [Representational image]
  • ASOS says hackers accessed names, addresses, phone numbers and email details.
  • Recent customer search histories, including terms such as “glamorous wide fit”, were also exposed.
  • Passwords and payment card information were not accessed, according to ASOS.

ASOS has revealed that hackers gained access to millions of customers’ recent search histories, as well as names, addresses, phone numbers and email details, in a cyber attack on the online fashion retailer.

Searches including “glamorous wide fit”, “ASOS petite” and “reclaimed vintage” were among the information accessed, according to reports. The disclosure gives a clearer picture of the breach after ASOS initially said only basic personal information may have been affected.


The incident emerged on Thursday (6) when customers received a notification through the ASOS app titled “ASOS hacked”, directing them to a Telegram channel. ASOS subsequently confirmed that the notification had been sent by an unauthorised third party.

Following what the company described as a detailed 48-hour investigation, ASOS said an unauthorised party had gained access to an employee account by impersonating a trusted contact and obtaining login credentials.

ASOS said the credentials were then used to access information held on certain third-party platforms.

The company said payment card information and account passwords had not been accessed.

What information did ASOS hackers access?

ASOS said basic personal information including names and contact details was accessed. This included delivery and email addresses and phone numbers.

The company also said hackers accessed “certain non-personal account related information”. The BBC reported that this included customers’ recent search history after it was contacted by the people claiming responsibility for the attack.

That means the exposed information could reveal not only who a customer is and how to contact them, but also what they have been looking for on the fashion site.

For example, searches such as “glamorous wide fit” or “ASOS petite” could provide additional context that makes a scam message or phone call appear more convincing.

ASOS said in its customer message: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials.”

It added that the affected platforms were “immediately locked down” and that it had launched a full investigation with internal and external cyber experts, while working with law enforcement and regulatory authorities.

ASOS has around 16.5 million active customers across more than 100 markets, according to its latest corporate information.

The breach appears to have involved social engineering rather than a direct attack on ASOS’s main website or app.

According to ASOS, the attackers impersonated a trusted contact to persuade an employee to provide login credentials. Those credentials were then used to access information on third-party platforms used by the retailer.

The distinction is important because ASOS has said its website and app remain safe to use.

The hackers initially claimed in their Telegram message that they had compromised a “Snowflake instance”, referring to the cloud data platform. However, ASOS has said the access involved third-party platforms and an employee account. There is no confirmation from ASOS that Snowflake itself was breached.

The incident also highlights a wider problem for companies that rely on outside technology providers. ASOS has previously identified cyber attacks involving third-party systems as a business risk, noting that unauthorised access can result in data loss, operational disruption and loss of customer confidence.

What should ASOS customers do now?

ASOS says customers do not need to take any action and that its website and app are safe to use.

However, the company is warning customers to be particularly cautious about unexpected calls, texts or emails claiming to be from ASOS.

“Please remain cautious of unexpected messages or calls claiming to be from Asos,” the company said. “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”

The warning matters because exposed personal information can make phishing attempts look much more authentic. A scammer who knows a customer's name, phone number and shopping interests could potentially create a highly personalised message.

Cybersecurity expert Trevor Dearing of Illumio warned that criminals could use details from the attack to make fraudulent messages appear genuine and create a sense of urgency.

ASOS has said it will contact customers directly where its investigation finds that additional information, support or action is required.

Bloomberg Intelligence analyst Charles Allen also warned that the incident could have a commercial impact, saying the hack might “temporarily cap the pace” of ASOS's efforts to revive sales and profits.

“The loss of customer trust could weigh on efforts to rebuild its client base,” he said.

For customers, the immediate risk is therefore not necessarily someone using an exposed password or payment card. It is the possibility of more convincing impersonation and phishing attempts based on information that customers may not realise they have shared with a retailer.

ASOS said it had already taken additional steps to strengthen its security controls following the attack.

Add EasternEye As Your Trusted Source
preferred source on google news

More For You

Trump's Iran strike

Oil prices have climbed above $105 a barrel as fears of renewed US strikes on Iran grow

Getty Images

Oil prices jump as Trump considers renewed Iran strikes. Here’s what could happen next

  • Brent crude climbed above $105 a barrel on Thursday.
  • US petrol is averaging more than $4.36 a gallon, while diesel is above $6.
  • A wider conflict could put further pressure on energy prices and global borrowing costs.

Oil prices surged on Thursday as investors reacted to reports that President Donald Trump is considering renewed large-scale US military strikes against Iran, with Brent crude moving above $105 a barrel.

Brent rose almost 5 per cent to around $105 a barrel, while US West Texas Intermediate crude climbed more than 4.5 per cent to around $92. Reuters reported that the move was also being driven by increased attacks on shipping in the Gulf and Strait of Hormuz, alongside concerns about disrupted US oil production.

Keep ReadingShow less