Asos Customer Data Breach More Extensive Than Initially Revealed
Online fashion retailer Asos has confirmed that detailed personal data of millions of its customers has fallen into the hands of cybercriminals.
Online fashion retailer Asos has announced that cybercriminals have accessed detailed profiles of potentially millions of its users. Initially, it was stated that only basic contact details might have been compromised. However, cybercriminals contacted BBC News claiming the breach was more extensive, a fact now confirmed by Asos.
Highlights
- Cybercriminals have obtained names, addresses, phone numbers, emails, and customer numbers of Asos users.
- The stolen data also includes customer search queries on the website, such as "reclaimed vintage" or "Asos petite."
- Asos confirmed that no bank details or passwords were accessed but warned customers about potential phishing attacks.
- The attackers claim they gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials and download customer data.
- The cybercriminals assert they used Simon AI, a platform built on top of Snowflake, a data storage and analysis company, to access the data.
Details
Asos initially disclosed that only basic contact information might have been compromised. However, after the BBC was contacted by the cybercriminals responsible, it became clear the extent of the breach was far greater. The information obtained by the cybercriminals includes not only contact details but also personal profile data such as customers' website search histories. This significantly increases the risk of scammers crafting more convincing phishing emails or phone calls.
In its email to customers, Asos confirmed that data profiles were taken but reiterated that no bank details or passwords were accessed. Asos urged customers to remain cautious of unexpected messages or calls, stating they would never ask for passwords, security codes, or payment details through unsolicited communications. The company has not yet responded to questions regarding the full scale of the breach.
Cybercriminals previously used Asos's own app system to send a pop-up notification to potentially millions of users. Asos later confirmed to the London Stock Exchange that this notification was sent by an "unauthorised third party" and that "basic personal information including name and contact details may have been accessed." Cybersecurity experts recommend changing passwords as a precaution and being vigilant for suspicious activity.
Why it matters
This data breach poses a significant risk to millions of Asos customers who shop online. The detailed personal information stolen could lead to more sophisticated phishing and scam attempts. This incident once again highlights the critical importance of protecting customer data and the continuous need for companies to strengthen their cybersecurity measures.