Asos hackers took more personal details than first revealed, BBC finds
ASOS’s latest breach has turned a routine data‑theft story into a full‑blown cautionary tale for anyone who shops online. Names, addresses, phone numbers, emails and even the search terms shoppers typed into the site are now in the hands of a group calling itself Xuanyewen.
ASOS’s latest breach has turned a routine data‑theft story into a full‑blown cautionary tale for anyone who shops online. After the BBC was contacted by the very criminals who claimed the hack, the fashion retailer confirmed that “detailed profiles” of potentially millions of users have been siphoned off. Names, addresses, phone numbers, emails and even the search terms shoppers typed into the site are now in the hands of a group calling itself Xuanyewen. The fallout is already rippling through the UK’s digital‑consumer landscape, prompting warnings from security experts and a fresh look at how retailers guard the data that fuels their business.
What the hackers actually got
The breach goes beyond the “basic contact details” ASOS initially disclosed. In addition to the usual identifiers, the stolen files contain the exact search queries customers entered – phrases like “reclaimed vintage”, “glamorous wide fit” and “ASOS petite”. Those breadcrumbs reveal personal style preferences, size data and even buying intent, turning a simple address list into a rich profile that can be weaponised for targeted phishing.
ASOS reassured users that “no bank details or passwords were accessed”, but the company stopped short of quantifying the breach’s scale. The lack of a concrete figure leaves the public guessing just how many profiles were compromised, while the fact that the data includes searchable behaviour raises the stakes for fraudsters looking to craft believable scams.
How the hackers slipped in
According to ASOS, the attackers gained entry through an employee account by “impersonating a trusted contact to obtain login credentials”. Once inside an unnamed service, they were able to download the customer data. The same breach vector was used to push a fake pop‑up notification through the ASOS app, a move that amplified the attack’s reach by targeting “potentially millions of people” directly on their phones.
The pop‑up claimed the hackers had “compromised the Snowflake instance”. Snowflake, a cloud‑based data‑storage platform, has been cited in past breaches, but the company itself said its platform had not been breached. The criminals said they used a tool built on Snowflake called Simon AI to harvest the data, though Simon AI declined to comment.
The fake app notification that set off alarms
On Tuesday, users reported a sudden in‑app pop‑up that warned of a data breach. ASOS later confirmed the message was sent by an “unauthorised third party”. The notification was the first public sign that the breach had moved from a backend compromise to a direct consumer‑facing attack, prompting the retailer to alert shareholders via the London Stock Exchange and to send a similarly worded email to customers.
The timing of the pop‑up—coinciding with the BBC’s outreach—suggests the hackers were trying to sow panic and possibly harvest additional credentials by prompting users to click through the fraudulent alert. The episode underscores how a breach can evolve from a silent data exfiltration into an active social‑engineering campaign.
What experts say about the risk
Security specialists warn that the stolen profile data makes phishing far more convincing. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, stressed that “passwords have not been stolen, so be highly suspicious of any unsolicited text or email asking you to change or share yours.” He added that scammers are likely to reference the breach itself, using personal details to appear legitimate and creating urgency—like threatening to lock accounts within 24 hours.
Because the breach includes search histories, fraudsters could tailor scams around a shopper’s recent interests, increasing the likelihood of a successful lure. The advice from experts is simple but stark: treat any unexpected contact from “ASOS” with skepticism, and never share passwords, security codes or payment details through unsolicited channels.
ASOS’s response and next steps
In its customer email, ASOS reiterated that it would never request passwords, security codes or payment details via an unsolicited message or call. The retailer also promised to “contact customers directly where we believe additional information, support or action may be required” and said its website and app remain safe to use. Beyond that, ASOS claimed it has taken “additional steps to further strengthen security controls,” though it did not detail what those measures entail.
The company’s silence on the breach’s magnitude leaves investors and shoppers in the dark. While the firm confirmed that the pop‑up was sent by an “unauthorised third party”, it has not disclosed how many accounts were accessed or whether any other internal systems were compromised. The lack of transparency fuels speculation and could pressure ASOS to reveal more as regulatory scrutiny intensifies.
What this means for the wider retail sector
The ASOS incident highlights a growing trend: attackers are moving beyond stealing credit‑card numbers to harvesting richer behavioural data that can be monetised in more sophisticated fraud schemes. Retailers that rely on cloud‑based analytics platforms like Snowflake may find themselves exposed if third‑party tools such as Simon AI are not rigorously vetted.
For consumers, the breach serves as a reminder that even “basic” personal information can be weaponised. As online shopping continues to dominate, shoppers will need to stay vigilant, regularly update passwords, and monitor accounts for suspicious activity—especially when a brand they trust issues a breach alert.
How to protect yourself now
First, treat any unexpected ASOS communication as potentially fraudulent. Verify the sender’s email address or phone number against official contact details before responding. Second, consider changing your ASOS password as a precaution, even though the breach did not expose passwords. Third, watch for phishing attempts that reference the breach, your name, address or recent search terms, and report any suspicious messages to ASOS’s support channels.
Finally, keep an eye on your credit reports and banking statements for unusual activity. While the breach did not involve direct financial data, the combination of personal identifiers and shopping preferences creates a fertile ground for identity‑theft schemes. Staying alert now can help you dodge the next wave of scams that are likely to ride on the back of this high‑profile hack.
This article was produced with AI-assisted research and editorial support. Reporting is based on the source material cited below. Sources: BBC Technology; bbc.co.uk; Global1.News (08 October 2026).
By Nova Chen, Staff Writer
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)