Online fashion retailer Asos has confirmed that hackers have accessed far more sensitive customer data than the company initially acknowledged. While Asos first reported that only "basic contact details" may have been compromised following Tuesday's breach, the retailer now admits that detailed customer profiles including names, addresses, phone numbers, email addresses, and customer identification numbers have been stolen. The expanded disclosure came after cyber criminals contacted news outlets with samples of the stolen data, revealing the true scale of the incident. Notably, the hackers also obtained records of customer search histories on the platform, capturing specific fashion queries like "reclaimed vintage," "glamorous wide fit," and "Asos petite." The company maintains that bank details and passwords were not accessed, though it has not publicly disclosed how many customers were affected.
Investigations reveal the breach occurred through a social engineering attack targeting an Asos employee. Hackers impersonated a trusted contact to obtain login credentials for an unnamed service, then used those credentials to access customer data stored in a Snowflake instance—a cloud-based data storage and analysis platform. During the initial attack on Tuesday, hackers exploited Asos's own app notification system to send pop-up messages to potentially millions of users, alerting them to the breach. The cyber criminals, identifying themselves as Xuanyewen, claimed they used Simon AI, a platform built natively on top of Snowflake, to gain access to the customer database. Snowflake has previously faced breaches due to unauthorized logins at other companies, though the company stated its own platform infrastructure was not compromised in this instance.
The theft of comprehensive customer profiles creates significant vulnerability to sophisticated phishing and fraud schemes. With access to names, addresses, phone numbers, email addresses, and search history, scammers can craft highly targeted and convincing impersonation attacks. Email and telephone-based phishing campaigns can now exploit detailed knowledge of individual customer behavior and preferences, dramatically increasing their effectiveness. Asos has warned customers to remain cautious of unsolicited messages or calls claiming to originate from the company, emphasizing that legitimate Asos communications will never request passwords, security codes, or payment details through unexpected contact.
Asos has stated that its website and app remain safe to use and that customers should not take any immediate action, though cybersecurity experts have recommended users change their passwords as a precautionary measure. The company said it has implemented additional security controls to strengthen defenses following the breach. The retailer emphasized its commitment to protecting customer information and stated it takes that responsibility seriously. However, Asos has not provided specific details about the total number of affected customers or a comprehensive timeline of events. The company is continuing its investigation into how the breach occurred and how the initial employee account compromise happened.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free