News · Science & Technology

Asos hackers took more personal details than first revealed, BBC finds

Asos hackers took more personal details than first revealed, BBC finds

The stolen information went far beyond the basic contact details Asos first mentioned. Criminals obtained names, addresses, phone numbers, email addresses, customer numbers and dates of birth. They also accessed customers’ searches on the Asos website, creating unusually detailed profiles of users. For example, one customer’s searches included “reclaimed vintage”, “glamorous wide fit” and “Asos petite”. The stolen data also showed that Harriet had used Asos since 2019. These details can help criminals understand a person’s identity, interests and relationship with the retailer. Asos confirmed that passwords and bank details were not accessed. However, the company did not state how many records were taken. It is investigating the breach and warned customers to be cautious about unexpected messages or calls claiming to be from Asos.

Based on reporting by BBC UK

What personal information did hackers obtain from Asos customers, and what information was not accessed?

The stolen information went far beyond the basic contact details Asos first mentioned. Criminals obtained names, addresses, phone numbers, email addresses, customer numbers and dates of birth. They also accessed customers’ searches on the Asos website, creating unusually detailed profiles of users.

For example, one customer’s searches included “reclaimed vintage”, “glamorous wide fit” and “Asos petite”. The stolen data also showed that Harriet had used Asos since 2019. These details can help criminals understand a person’s identity, interests and relationship with the retailer.

Asos confirmed that passwords and bank details were not accessed. However, the company did not state how many records were taken. It is investigating the breach and warned customers to be cautious about unexpected messages or calls claiming to be from Asos.

What is a data breach, and how did the attackers get into Asos's systems?

A data breach happens when people who are not authorised gain access to an organisation’s information. It matters because the exposed data can be copied, downloaded or used for further attacks. The Asos incident involved customer profiles rather than passwords or bank details, according to the company.

Asos said attackers impersonated a trusted contact to obtain login credentials from an employee. They then used that login for an unnamed service and downloaded customer data. The criminals claimed they had compromised a Snowflake instance and said they used Simon AI, a platform built on Snowflake, to reach the information.

The exact route remains under investigation. Snowflake said its platform had not been breached, so the article describes unauthorised login access rather than a confirmed attack on Snowflake itself. Asos said it took additional steps to strengthen security controls.

How many customers could be affected by the stolen profiles?

The article does not give a precise number of affected customers. Asos told customers that detailed profiles of potentially millions of users were in criminals’ possession. The company also did not respond to questions about the breach’s scale.

The estimate reflects the reach of the incident. Cyber criminals used Asos’s own app system to send a pop-up notification to potentially millions of people. They later shared sample stolen data with the BBC, showing that the information taken included names, contact details, dates of birth, customer numbers and website searches.

The current reality is therefore broad potential exposure, not a confirmed total. Asos said it was still investigating and would contact customers directly if additional information, support or action was needed. Customers were told to remain cautious about unexpected messages and calls claiming to be from Asos.

How could criminals use stolen names, addresses, dates of birth and search histories to make phishing messages or phone calls seem genuine?

Stolen personal details can make a scam appear to come from a trusted company. A message using someone’s real name, address, birth date or Asos customer number may seem more credible than a generic email. The same information can help a caller sound familiar when claiming to discuss an account or order.

Search histories add another layer of personal context. The article gives searches such as “reclaimed vintage”, “glamorous wide fit” and “Asos petite”. A criminal could mention one of these interests while pretending to be from Asos, making the contact seem connected to the customer’s actual activity.

The article warns that scammers may mention the attack and use personal details to seem genuine. They may also create urgency, such as threatening to lock an account within 24 hours. Customers should distrust unsolicited requests for passwords, security codes or payment details.

Why can a breach still be dangerous even when passwords and bank details have not been stolen?

A breach can remain dangerous because information does not need to include passwords or payment details to support fraud. Names, addresses, phone numbers, birth dates and shopping activity can help criminals build convincing messages or calls. This increases the chance that a victim will trust the contact.

For example, a scammer could mention the Asos attack, use a customer’s real details and claim that urgent action is required. The warning from security expert Trevor Dearing describes a possible threat to lock an account within 24 hours. The goal could be to persuade someone to reveal a password, security code or payment detail.

Asos said passwords and bank details were not accessed and customers did not need to take action. Still, experts advised changing passwords as a precaution and watching for suspicious activity. Asos specifically warned that it would never request passwords, security codes or payment details through unsolicited contact.

How did impersonating a trusted contact help the attackers obtain an employee's login credentials?

Impersonating a trusted contact means presenting yourself as a person or contact the employee is likely to recognise and believe. That trust can make a request for login credentials appear routine rather than suspicious. Asos identified this impersonation as the way attackers gained access to an employee account.

The article does not explain exactly how the criminals contacted the employee or what they said. It does state that they obtained login credentials after impersonating a trusted contact. With those credentials, they logged into an unnamed service and downloaded customer data.

This made the employee account the route into the information. Asos said it was still investigating the breach and had taken additional steps to strengthen security controls. The criminals claimed to have compromised Snowflake and used Simon AI, but Snowflake said its platform had not been breached. The confirmed account-access mechanism was unauthorised use of obtained credentials.

What are cloud data platforms such as Snowflake, and why can a stolen login expose stored customer data without the platform itself being hacked?

Cloud data platforms such as Snowflake are services organisations use to store and analyse data through systems hosted by a provider. They can hold or connect to large datasets, including customer information. This matters because access is often controlled through user accounts and permissions.

If criminals obtain a valid employee login, they may be able to enter an authorised service and download data that account can reach. In that situation, the attackers exploit stolen credentials rather than breaking the platform’s underlying technology. The Asos article says hackers used an employee account and an unnamed service to download customer data.

The criminals claimed they had compromised a Snowflake instance and used Simon AI, which is built on Snowflake. Snowflake said its platform had not been breached. Therefore, the article supports a distinction between a stolen login exposing connected data and a confirmed breach of Snowflake itself. Asos continued investigating the route taken.

Key Facts:

📌 Hackers obtained names, addresses, phone numbers, emails and dates of birth.

📌 Customer searches and customer numbers were also exposed.

📌 Asos said passwords and bank details were not accessed.

📌 A data breach involves unauthorised access to an organisation’s information.

📌 Attackers impersonated a trusted contact to obtain employee credentials.

📌 The stolen customer data was downloaded through an unnamed service.

📌 Potentially millions of Asos users may be affected.

More on JupiteX