ASOS confirms customer data accessed in cyber attack

ASOS has confirmed that hackers accessed customers’ personal information, including names, addresses, phone numbers and email addresses, after impersonating a trusted contact to obtain an employee’s login credentials, following a cyber attack disclosed on Tuesday.

The online fashion retailer said on Thursday that the attackers used the compromised account to access information held on certain third-party platforms. ASOS said payment card details and account passwords had not been accessed, while its website and app remained safe to use.

The company’s investigation found that the attackers had obtained some personal information and other account-related data. The Guardian reported that the latter included customers’ recent search histories, potentially revealing shopping preferences and making subsequent scams more convincing.

ASOS said it had immediately locked down the affected platforms to prevent further unauthorised access and launched an investigation with internal and external cybersecurity experts. The retailer is working with law enforcement and regulatory authorities and said it had introduced additional security controls.

In a message to its 16.5 million customers on Thursday, ASOS apologised for the uncertainty caused by the incident and advised shoppers to exercise caution over unexpected communications claiming to come from the company. It said customers did not need to take action on their accounts but would be contacted directly if further measures became necessary.

The incident emerged on Tuesday when customers received a notification through the ASOS app claiming the retailer had been hacked and threatening to leak data. The message included a link to a Telegram channel associated with a group calling itself Xuanye Group.

Snowflake, the cloud data platform named in the notification, said it had found no compromise of its own systems. ASOS said the attackers had accessed information through third-party platforms rather than confirming a breach of its main website or app.

Cybersecurity experts warned that the exposed information could enable targeted phishing attempts. Commenting on the news, Paul Arnold, chief executive of the Information Commission's Office told users that they should ‘stay alert’ following the breach, adding: “Be cautious of any links or attachments, and do not click on links in unexpected texts or emails claiming to relate to your account.”

Lisa Barber, technology editor at consumer watchdog Which?, advised shoppers to be particularly wary of unexpected calls, texts and emails in the coming weeks and months.

The attack has also raised concerns about ASOS’s efforts to restore its business performance. Shares fell by more than 13 per cent after the incident became public on Tuesday, although City AM reported that they recovered following Thursday’s update. Charles Allen, an analyst at Bloomberg Intelligence, said the loss of customer trust could weigh on efforts to rebuild the retailer’s client base.



Share Story:

Recent Stories


From CapEx to AI: Understanding the evolving cost structure of retail technology
This Retail Systems webinar, sponsored by Aptos, brings together leading voices from across the retail technology ecosystem to examine how modern PoS has transformed the cost ownership model – and how the emergence of agentic commerce is poised to rewrite the rules once again.

Beyond Channels: Redefining retail with Unified Commerce
This Retail Systems fireside chat with Nikki Baird, Vice President, Strategy & Product at Aptos will explore how unified commerce strategies enable retailers to tear down these barriers and unlock new levels of operational agility and customer satisfaction.

Advertisement