Asos hackers took more personal details than first revealed, BBC finds

by | Oct 8, 2026 | Technology

Asos hackers took more personal details than first revealed, BBC finds

Asos has notified customers that the scope of a data breach is significantly broader than initially reported, following contact between the retailer and BBC News. The hackers responsible have disclosed that they obtained comprehensive customer profiles containing names, addresses, phone numbers, email addresses, and customer identification numbers. Additionally, the stolen data includes records of searches performed by users on the platform, encompassing terms related to specific product categories and customer preferences.

The expanded data access creates elevated risks for affected individuals. Scammers could potentially use the detailed personal information and search history to conduct targeted phishing campaigns or impersonation schemes. Asos has advised customers to remain vigilant about unsolicited communications claiming to represent the company and reminded them that legitimate Asos representatives will not request passwords, security codes, or payment information through unexpected messages or calls.

In its initial disclosure earlier this week, Asos stated that only basic contact information had been accessed. However, the company confirmed to customers that no bank details or passwords were compromised in the incident. The company indicated it is continuing an investigation into the breach methodology.

According to Asos, the unauthorized access occurred after cyber criminals impersonated a trusted contact to obtain login credentials for an employee account. Using these credentials, the attackers accessed an unnamed service and downloaded customer data. The cyber criminals, identifying themselves as Xuanyewen, claimed in communications to BBC News that they used a platform built on Snowflake, a data storage and analysis service, to obtain the information. Snowflake has previously stated its platform itself was not breached.

Asos stated that its website and application remain secure for customer use and emphasized its commitment to information security. The company said no immediate action is required from customers, though cybersecurity specialists have recommended users change their passwords as a precautionary measure and monitor accounts for suspicious activity.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI