Asos Reveals Hackers Accessed More Personal Data Than Initially Thought
A cyber attack on online retailer Asos has potentially affected millions of its customers, with hackers gaining access to sensitive data including names, addresses, phone numbers, and search history.

Online retailer Asos has revealed that hackers have accessed far more personal information than initially thought, potentially affecting millions of its customers.
According to sources contacted by BBC News, cyber criminals claim to possess detailed profiles of Asos users, including names, addresses, phone numbers, emails, and customer numbers. This sensitive data was not part of the initial warning sent out by Asos after the breach occurred. The company had initially stated that only basic contact details might have been accessed.
The hackers also appear to have gained access to search history on the website, which could be used for phishing attacks or impersonation scams. Customers who searched for specific items such as "reclaimed vintage" or "Asos petite" may now see their searches exposed in the stolen data. This information can be used by scammers to craft targeted emails or phone calls.
In an email to customers, Asos confirmed that data profiles were taken but emphasized that no bank details or passwords were accessed. The company warned customers to remain cautious of unexpected messages or calls claiming to be from Asos and urged them never to share sensitive information through unsolicited communication.
Asos's investigation into the high-profile hack continues, with the company still unsure how the cyber criminals gained access to its system. According to Asos, hackers impersonated a trusted contact to obtain login credentials for an employee account, allowing them to download customer data.
The stolen data includes more than just basic personal information such as name and contact details, which was initially thought to be the extent of the breach. The cyber criminals shared a sample of the stolen data with the BBC, revealing that they had access to a wider range of sensitive information.
Asos has confirmed that hackers used an unnamed service to download the customer data after gaining access to the employee account. This service is believed to be connected to Snowflake, a popular data storage and analysis company whose customers have been breached in the past due to unauthorised log ins.
The exact nature of the connection between Asos's system and Snowflake remains unclear, as does the extent of the damage caused by the hack. Asos has warned customers to remain cautious of unexpected messages or calls claiming to be from the company, urging them never to share sensitive information through unsolicited communication.
The hackers behind the Asos data breach have revealed that they used a platform built on top of Snowflake to gain access to customer information.
This platform, called Simon AI, has been contacted for comment but its response is yet to be received. Meanwhile, Snowflake had previously stated that its platform was not breached in the incident.
The revelation raises questions about how the hackers managed to access sensitive data, despite Snowflake's claims of security.
Asos has assured customers that they are not required to take any action following the breach, but cyber security experts recommend changing passwords as a precautionary measure and being vigilant for suspicious activity.
Facts based on reporting originally published by BBC News Technology.
You may republish this story, in full or in part, if you credit Noti Group and link to it (licence CC BY 4.0). Photos are not included.











