Asos warns customers about full extent of data breach after BBC contacted by hackers
Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.

Asos warns customers about full extent of data breach after BBC contacted by hackers
Asos has informed customers that hackers now hold detailed profiles of potentially millions of the online retailer’s users.
The update came after BBC News told the company it had been approached by cyber criminals who said this week’s breach went further than the “basic contact details” Asos had previously said may have been accessed.
Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.
Customer searches on the website are also included. Search terms such as “reclaimed vintage”, “glamorous wide fit” and “Asos petite” can be seen in the data.
With this information, scammers could potentially create highly convincing phishing emails or phone calls.
The danger to individuals is now greater, and customers are being warned about possible impersonation scams.
In an email to customers, Asos confirmed that data profiles were taken, but said no bank details or passwords were accessed.
“Please remain cautious of unexpected messages or calls claiming to be from Asos,” it said.
“We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
The company did not answer questions about the size of the breach.
The high-profile hack made global headlines on Tuesday when cyber criminals used Asos’s own app system to send a pop-up notification to potentially millions of people.
Later that day, the firm told shareholders via the London Stock Exchange that the pop-up had been sent by an “unauthorised third party” and that “basic personal information including name and contact details may have been accessed.”
The company then emailed customers with similar wording.
On Wednesday evening, the cyber criminals behind the attack contacted the BBC and shared a sample of the stolen data, revealing the true scale of the hack.
The BBC delayed publishing this article so Asos could contact its customers first.
Asos said it is still investigating how the hack occurred.
It told customers that hackers “gained access to an Asos employee account by impersonating a trusted contact to obtain log in credentials”.
Using that log in to an unnamed service, the hackers were able to download customer data.
In the pop-up notification sent to customers by the hackers, they claimed they had “compromised the Snowflake instance”.
Snowflake is a widely used data storage and analysis company whose customers have previously been breached because of unauthorised log ins.
The cyber criminals, who call themselves Xuanyewen, told the BBC they used a platform built natively on top of Snowflake — called Simon AI — to access the data.
Simon AI has been contacted for comment. Snowflake has previously said its platform was not breached.
Asos said customers do not need to take any action.
However, cyber security experts have advised users to change passwords as a precaution and stay alert for suspicious activity.
Asos said its website and app are safe to use and “we know our customers trust us with their information”.
“We take that responsibility seriously and have already taken additional steps to further strengthen security controls,” it said.

