THURSDAY, OCTOBER 8, 2026|No. 17981
Technology · Retail

Asos Data Breach Exposes More Than Basic Contact Details

Asos has confirmed that a recent data breach exposed more extensive personal information than initially disclosed, including names, addresses, and search histories.

An illustration representing a cyber security breach and data protection.
An illustration representing a cyber security breach and data protection.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
1 countries
Related coverage

Asos has informed its customers that hackers are in possession of detailed profiles of potentially millions of users of the online store. This update came after the BBC informed the retailer that cyber criminals had contacted them, stating that this week's breach went beyond the "basic contact details" Asos had initially disclosed.

Names, addresses, phone numbers, emails, customer numbers, and dates of birth are now in the hands of criminals. One victim told the BBC it was "very unsettling" that the hackers now possess this information about her.

The criminals also have access to the search histories of customers on the website. Terms such as "reclaimed vintage", "glamorous wide fit", and "Asos petite" are visible in the data. Harriet, who has been using Asos since 2019, is another detail the hackers now know.

"What I find particularly worrying is the possibility that stolen data can be used as a tool for future attacks, meaning the impact of a breach could extend well beyond the initial incident," she said. With the stolen information, scammers may be able to create convincing phishing attack emails or phone calls. The risk to individuals is now higher, and customers are being warned about potential impersonation scams.

In its email to customers, Asos confirmed that data profiles were taken but stated that no bank details or passwords were accessed. "Please remain cautious of unexpected messages or calls claiming to be from Asos," it said. "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call." The company did not respond to questions about the scale of the breach.

Customers saw this pop-up notification on Tuesday.

The high-profile hack made global headlines on Tuesday when cyber criminals used Asos's own app system to send a pop-up notification to potentially millions of people. Later that day, the firm confirmed to shareholders via the London Stock Exchange that the pop-up was sent by an "unauthorised third party" and "basic personal information including name and contact details may have been accessed." The company then sent an email to customers with similar wording.

On Wednesday evening, the cyber criminals responsible contacted the BBC, sharing a sample of the stolen data which revealed the true extent of the hack. The BBC delayed publishing this article to allow Asos to contact its customers first.

'Impersonating a trusted contact'

Asos stated it is still investigating the data breach and will "contact customers directly where we believe additional information, support or action may be required".

The UK fashion site explained to customers that hackers gained access to an Asos employee account by "impersonating a trusted contact to obtain log in credentials". With that login to an unnamed service, the hackers were able to download the customer data.

In the pop-up notification sent to customers by the hackers, they claimed they had "compromised the Snowflake instance". Snowflake is a popular data storage and analysis company whose customers have been breached in the past due to unauthorised logins.

The cyber criminals, calling themselves Xuanyewen, claimed to the BBC they used a platform built natively on top of Snowflake, called Simon AI, to gain access to the data. Simon AI has been contacted for comment. Snowflake previously said its platform had not been breached.

Asos said customers are not being asked to take any action. However, cyber security experts have warned users to change passwords as a precaution and be on alert for suspicious activity.

"Passwords have not been stolen, so be highly suspicious of any unsolicited text or email asking you to change or share yours," said Trevor Dearing, Senior Director of Critical Infrastructure at Illumio. "Expect scammers to mention the attack, use your personal details to seem genuine, and create urgency, such as threatening to lock your account within 24 hours."

Asos said its website and app are safe to use and "we know our customers trust us with their information". "We take that responsibility seriously and have already taken additional steps to further strengthen security controls," it said.

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →

Earlier on PAN

More in Technology →