← All articles
EXPLAINED

ASOS confirms customer contact details were exposed

ASOS has confirmed that some customers’ names and contact details were exposed after the ‘ASOS HACKED’ alert. Here’s what changed and what to check.

Sophia, HackRisk’s AI security analyst, checking a customer contact list with a shop owner, with the headline ‘ASOS confirms customer contact details were exposed’

On Tuesday, ASOS app users received a push notification titled “ASOS HACKED”. Our first post said ASOS hadn’t confirmed a breach. Since then, ASOS has confirmed it, explained how the attackers got in, and widened what it says was taken.

What ASOS has confirmed

On Tuesday, ASOS told shareholders through the London Stock Exchange that an unauthorised third party sent the notification, and that basic personal information, including names and contact details, may have been accessed. It sent customers an email with similar wording.

On Wednesday evening, the attackers sent the BBC a sample of the stolen data. ASOS then updated customers, confirming that the hackers hold detailed profiles. The BBC reports that these include names, addresses, phone numbers, email addresses, customer numbers and dates of birth, plus the searches customers made on the website. ASOS says no bank details or passwords were accessed.

The BBC says the breach could affect potentially millions of users. ASOS didn’t answer its questions about scale, and it says its investigation is continuing.

How the attackers got in

ASOS says the attacker gained access to an employee account by impersonating a trusted contact to obtain login credentials. With that login to a service ASOS hasn’t named, the hackers were able to download customer data. Reports say the same access reached the platforms ASOS uses to message customers, which let the attacker send the notification.

This is social engineering: tricking a person into handing over access, instead of breaking the technology. ASOS hasn’t said who was impersonated, whether the approach came by email, phone or message, or whether multi-factor authentication was switched on.

What is still unclear

The alert claimed the attackers had compromised ASOS’s Snowflake data platform. Snowflake says its platform wasn’t breached. The attackers told the BBC they used a marketing platform built on top of Snowflake. ASOS hasn’t named any platform, and that claim is unverified.

ASOS hasn’t said how many customers are affected. It says it will contact customers directly where it believes they need more information, support or action.

What it tells small businesses

The way in was a person pretending to be someone an employee trusted. That approach works on businesses of any size, and it needs no special tools.

The result was a download of detailed customer profiles from one login. Most small firms hold the same kind of data in their email marketing, SMS or CRM tools, and a single account can reach all of it.

What to do

If you use ASOS: ASOS says no bank details or passwords were accessed and isn’t asking customers to take action. The details that were taken still let a scammer sound genuine. Experts expect messages that mention the breach, use your personal details and create urgency, such as threatening to lock your account within 24 hours. ASOS says it will never ask you to share passwords, security codes or payment details through an unsolicited message or call.

The ICO’s advice is to avoid links in unexpected texts or emails about your account, log in through the official website or app, watch your bank accounts for unusual activity, and use strong, unique passwords with multi-factor authentication. Some experts also suggest changing your password as a precaution, especially if you reuse it elsewhere.

If you run a business: The attackers got in by tricking a person, so the most useful steps are habits your team can follow, plus a few settings that limit the damage if someone is fooled.

  1. Check before you act. If anyone asks for a login, a code, access or a password change, even someone you know, contact them on a number or channel you already hold, not the one in the message. Social engineering relies on you replying to the request itself.
  2. Treat codes as private. Turn on multi-factor authentication (MFA), a second proof such as a code from an app, for every admin login on your email, SMS, CRM and notification tools. Tell staff never to read out or approve a code they didn’t request, because that’s what an attacker will ask for next.
  3. Limit who can log in and export data. List who has admin access to the tools that hold your customer data or send messages in your name, and who can download your customer list. Remove leavers and anyone who doesn’t need it. Fewer logins means fewer people to trick.
  4. Make it safe to report. Tell your team to report odd requests, and any mistake, straight away with no blame. The sooner you hear, the sooner you can change passwords and restrict access.
  5. Prepare a customer message now. Draft a template so you can tell people quickly if something goes wrong, and agree who approves and sends it.

Sophia Says

“ASOS says the way in was a person pretending to be someone an employee trusted. That needed no clever technology, only a message that sounded right, and one login was enough to reach detailed customer data. The habit that helps is a simple one: when anyone asks for a login, a code or access, contact them on a number you already hold, and never share a code you didn’t ask for.”
“This is where HackRisk helps. Phishing Simulations let your team practise spotting a convincing request in a safe setting, and Security Awareness Training builds the habit of checking first. I also check whether your team’s logins are already circulating on the dark web, so a stolen one doesn’t sit unnoticed.”
— Sophia, HackRisk AI Security Analyst