ASOS says breach exposed customer names and contact details

The retailer says passwords and payment-card information were not accessed. Its disclosure follows an unauthorised app notification on 6 October, while the number of affected customers remains unclear.

Pedestrians and traffic on Oxford Street in London.
Context photograph: Oxford Street in London, photographed on 15 July 2013. It does not depict ASOS or the reported data breach. Palickap (resized and converted to WebP). CC BY-SA 4.0.
LinkedInPostEmail
Save for later

British online fashion retailer ASOS said on 8 October that a cybersecurity breach earlier in the week exposed some customers' names and contact details, Reuters reported. The company said no payment-card information or account passwords were accessed, but the number of customers affected and their locations remain unclear.

The disclosure, made in a customer email described by Reuters, follows an unauthorised push notification that ASOS says some customers received on 6 October. The retailer says it is investigating unauthorised activity involving third-party platforms used for customer communications.

What ASOS says was accessed

According to the customer email reported by Reuters, the information accessed included personal details and certain non-personal account-related information. The report does not identify those additional account fields, leaving the full scope of the exposure unspecified.

The statement that passwords and payment-card information were not accessed is ASOS's assessment. Reuters attributes it to the company's email; the report does not present an independently published forensic finding confirming the boundaries of the breach.

ASOS's public customer-care notice uses more tentative wording. It describes names and contact details as potentially accessed and says the company does not believe passwords or payment-card information were affected. The notice has no established publication timestamp, so its wording cannot establish the precise sequence of the company's assessments.

The firmer disclosure appears in the customer email described in the Reuters report published on 8 October. Neither that report nor the public notice provides a complete technical account of how the unauthorised access occurred or identifies a responsible party.

The 6 October notification and ASOS's response

In its customer-care notice, ASOS asks customers to disregard the unauthorised notification and avoid its external link. It dates that notification to 6 October, two days before Reuters reported the company's disclosure that personal information had been exposed.

ASOS says it restricted access and is working with internal and external specialist advisers and relevant authorities. Its description of the investigation refers to third-party communications platforms, but does not identify a specific compromised service or explain the access method.

The retailer says its website and app remain available for normal shopping. That assurance concerns the availability of its services; its notice also says the investigation is continuing and promises a further update when more information has been confirmed.

The ASOS customer-care FAQ says it is not currently requesting password changes or other action and will contact affected customers directly if that changes. It gives no deadline for resolving the incident or issuing its next update.

ICO warns about unexpected account messages

In an ASOS statement dated 7 October, the Information Commissioner's Office addressed the concern caused by messages from apparent hackers claiming access to personal information. Chief executive Paul Arnold said: “We would encourage anyone who receives a message of this nature to stay alert.”

The regulator cautioned against opening links or attachments in unexpected texts or emails about an account. Anyone choosing to change a password should go directly to the official website or app and make the change there, Arnold said.

The ICO also urged people to monitor bank accounts and online services for unusual activity and never provide personal or financial information in response to unexpected contact. Arnold highlighted strong, unique passwords and multi-factor authentication as general account protections.

Those remarks are precautionary guidance. The ICO statement does not announce an enforcement finding against ASOS or establish that customers have suffered fraud. It points people concerned about their personal information towards practical advice and support on the regulator's website.

What remains unknown about the breach

The Reuters report does not quantify the affected customers, identify affected countries or give a precise time when unauthorised access began. The 6 October notification date therefore establishes when that message was received, rather than when the underlying access started.

The published accounts do not establish that the data has been publicly released, that customers have lost money or that a ransom has been paid. ASOS's promised update remains the stated next step, with the extent of the exposure still incompletely described.

Sources and context

AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.

About NewsJaws Desk

AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.