Skip to content
REALNEWS HUB

Asos hackers took more personal details than first revealed, BBC finds

Retailer issues update after BBC contacted by cyber criminals who said this week's breach went beyond "basic contact details"

REALNEWS HUB Newsroom

A person holding a smartphone displaying an e-commerce fashion app next to delivered shipping packages on a wooden table.
REAL NEWS HUB

Online fashion retailer Asos has alerted shoppers that a recent cyber incident exposed more extensive personal customer records than the company initially acknowledged, following findings presented to the business by BBC News.

The retailer updated its assessment after cyber criminals reached out to the broadcaster claiming that the compromised information exceeded the basic contact details Asos had originally cited. A review of the data revealed that names, physical addresses, telephone numbers, email addresses, customer reference numbers, and search history queries on the site were taken. Specific search terms such as "reclaimed vintage", "glamorous wide fit", and "Asos petite" were included among the stolen records.

Security specialists warn that such granular details increase the threat of convincing phishing schemes and fraudulent communications. In notifications sent to shoppers, Asos verified that user profiles were taken while stressing that payment card data and account passwords were not accessed. The retailer urged users to remain vigilant against unexpected phone calls or messages purporting to be from the brand, reiterating that it never requests passwords, verification codes, or financial information through unsolicited outreach.

The incident first drew public attention earlier in the week when attackers hijacked the company's mobile application to deliver an unauthorised alert directly to potentially millions of device screens. Following that pop-up message, Asos notified the London Stock Exchange that an outside party had penetrated its systems and may have viewed basic personal information, a position it initially mirrored in messages to customers.

The perpetrators later shared sample files with BBC News to demonstrate the broader scope of the theft. The broadcaster delayed reporting the findings to provide Asos an opportunity to inform affected shoppers beforehand. While the retailer has not disclosed the full count of individuals impacted, it stated that it remains in the process of investigating the breach and will follow up with users should further steps become necessary.

According to Asos, the intruders gained entry by posing as a reputable contact to deceive an employee into handing over log-in credentials. Those credentials granted access to an external system, enabling the download of store records.

The hackers, operating under the name Xuanyewen, claimed in the app notification that they breached an instance of Snowflake, a cloud data storage platform. They further told the BBC that they compromised data using Simon AI, a service operating on Snowflake. Snowflake has previously maintained that its core platform was not infiltrated, while Simon AI was approached for comment.

Although Asos has not instructed customers to reset their credentials, independent security professionals advise shoppers to stay on high alert for impersonation scams. Specialists note that criminals may exploit the headlines and stolen browsing habits to fabricate urgent requests, such as false warnings about imminent account closures, in attempts to trick shoppers into revealing passwords or sensitive data. Asos maintained that its website and app remain safe for ongoing use and that it has reinforced its internal digital defences.

Spotted an error? Report it · Editorial standards · Corrections policy

Source & verification

Verified

Reported from Technology.

Get breaking news alerts and the Morning Briefing

Verified stories in your inbox, every one linked to its sources. All newsletters →

Newsletters

Free. Unsubscribe any time. See our privacy policy.