tech
Asos Breach Exposed 6 Personal Data Points, Not Just Contact Info

Asos has told customers that hackers obtained at least six categories of personal data — names, addresses, phone numbers, emails, customer numbers and dates of birth — reversing its earlier statement that only "basic contact details" might have been accessed, according to BBC News. The retailer updated customers after the BBC said it had been contacted directly by the hackers, who shared a sample of stolen data.
What personal data did the hackers actually take?
Asos's revised email to customers lists six specific data fields in criminal hands: name, address, phone number, email address, customer number and date of birth, BBC News reported. The stolen trove also includes behavioral data — the search terms individual customers typed into the Asos site, such as "reclaimed vintage," "glamorous wide fit" and "Asos petite," along with the date an account was created. One customer, identified only as Harriet, told the BBC the hackers now know she has used Asos since 2019. Asos said no bank details or account passwords were accessed.
How did the hackers get in?
Asos told customers the intrusion began when attackers gained access to an Asos employee account "by impersonating a trusted contact to obtain log in credentials," according to the company's email cited by BBC News. That stolen login let the hackers reach an unnamed internal service and download customer records. In its first public disclosure to shareholders via the London Stock Exchange on Tuesday, Asos described the intrusion more narrowly, saying an "unauthorised third party" had accessed the system and that "basic personal information including name and contact details may have been accessed." The hackers, who identified themselves to the BBC as a group called Xuanyewen, claimed they used a tool called Simon AI — built on top of the data-storage platform Snowflake — to carry out the breach. Snowflake customers have been hit by unauthorized-login breaches in prior incidents, the BBC noted. Asos did not confirm the hackers' technical account of how the breach occurred.
What is the timeline from first notice to full disclosure?
The breach became public Tuesday when the hackers used Asos's own app infrastructure to push a pop-up notification to what the company estimates could be millions of users. Asos confirmed the incident to shareholders that same day with the narrower "basic personal information" language, then emailed customers similar wording. On Wednesday evening, the hackers contacted the BBC directly and shared a data sample showing the breach was broader than disclosed. BBC News said it held publication to give Asos time to notify customers before the fuller scope became public.
What risk does this create for customers?
"What I find particularly worrying is the possibility that stolen data can be used as a tool for future attacks, meaning the impact of a breach could extend well beyond the initial incident," Harriet told the BBC.
She separately described it as "very unsettling" that hackers now hold these details about her. Asos's email to customers warned that the stolen names, contact details and account history could be used to build convincing phishing emails or phone calls impersonating the company. "Please remain cautious of unexpected messages or calls claiming to be from Asos," the company said, adding: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
What is Asos still not saying?
Asos has not responded to questions from the BBC about the total number of customer records affected, despite the pop-up notification reaching what the company has called potentially millions of users. The company said it remains in the investigation phase and will "contact customers directly where we believe additional information, support or action may be required." No regulatory filing or customer email reviewed by the BBC specifies a confirmed record count, a breakdown by country, or whether the six-field data profile applies to every affected account or only a subset. Asos has also not detailed what internal service the stolen employee credentials unlocked, beyond saying it allowed the download of customer data, nor has it confirmed or disputed the hackers' description of the Snowflake-linked tool used to extract it.
For now, the company's guidance to customers rests on two points that are verifiable from its own statements: passwords and bank details were not taken, and anyone contacted unexpectedly by someone claiming to represent Asos should treat the request as suspect.
Questions
What personal data did the Asos hackers steal?
Asos told customers the hackers obtained names, addresses, phone numbers, emails, customer numbers and dates of birth, plus account search history, according to BBC News.
Did the Asos hackers get passwords or bank details?
No. Asos said in its customer email that no bank details or passwords were accessed in the breach, per BBC News.
How did the Asos hackers gain access?
Asos said attackers impersonated a trusted contact to obtain login credentials for an employee account, then used that access to download customer data, the company told the BBC.