Asos has informed its customers that hackers have obtained detailed profiles of potentially millions of users. This update follows a report from BBC News, which revealed that cyber criminals claimed the breach included more than just "basic contact details" previously mentioned by Asos. The compromised data includes names, addresses, phone numbers, emails, and customer numbers, as well as search terms customers have used on the website, such as "reclaimed vintage" and "Asos petite."
As a result, there is an increased risk of phishing attacks targeting individuals. Asos has warned customers about potential impersonation scams but confirmed that no bank details or passwords were accessed. In an email to customers, the company advised them to remain cautious of unexpected messages or calls claiming to be from Asos, stating, "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
The breach gained significant media attention when hackers used Asos's app system to send a pop-up notification to millions of users. Later, Asos confirmed to shareholders via the London Stock Exchange that the notification was sent by an "unauthorised third party" and that basic personal information may have been accessed.
On Wednesday evening, the cyber criminals contacted the BBC, providing a sample of the stolen data, which revealed the extent of the breach. Asos is currently investigating how the hack occurred, stating that hackers accessed an employee account by impersonating a trusted contact to obtain login credentials. This access allowed them to download customer data. The hackers claimed to have compromised a Snowflake instance, a data storage and analysis service, but Snowflake has stated that its platform was not breached.
Asos has reassured customers that they are not required to take any immediate action, although cyber security experts recommend changing passwords as a precaution and being vigilant for suspicious activity. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, emphasized the importance of being cautious of unsolicited communications that may reference the attack. Asos has stated that its website and app remain safe to use and that it is taking steps to enhance security controls.