TechNews

Asos expands breach warning to customer profiles and shopping searches

Customer profiles and website searches were exposed alongside contact details, the BBC reports. Asos says passwords and bank details were not accessed, but the number affected remains unknown.

The facade of Greater London House in Camden, London.
File photograph of Greater London House in Camden, London, taken on 12 May 2012. Lobster1 (resized and converted to WebP). CC BY-SA 3.0.
LinkedInPostEmail
Save for later

Asos has warned customers that hackers obtained detailed profiles, including searches on its shopping website, according to a BBC report published on 8 October. The online retailer’s expanded disclosure goes beyond its earlier warning about basic contact information and gives customers more reason to scrutinise unexpected messages or calls claiming to come from the company.

The BBC reports that names, addresses, telephone numbers, email addresses and customer numbers are among the exposed information. Asos confirmed in a customer email that profiles were taken, but said bank details and passwords had not been accessed. That assurance is the company’s assessment, rather than a separately published forensic finding.

The development follows NewsJaws’ earlier report on the unauthorised Asos app notification. The change now is the disclosure of customer profiles and shopping searches, rather than just the notification itself or possible exposure of contact details.

What the Asos customer data includes

BBC cyber correspondent Joe Tidy reported that attackers contacted the broadcaster on Wednesday evening, 7 October, and shared a sample of stolen information. Asos issued its expanded warning after the BBC told the retailer about that contact.

Search terms visible in the data included “reclaimed vintage”, “glamorous wide fit” and “Asos petite”, according to the BBC’s reporting. These details extend the disclosure beyond information used simply to identify or contact a customer.

The BBC described potentially millions of users as affected, but said Asos did not answer its questions about the scale. There is no confirmed customer total, and the sample does not establish the complete contents of the stolen dataset. The countries involved and the period covered by the records also remain unclear.

How Asos has responded since the app notification

The incident became publicly visible on Tuesday, 6 October, when attackers used Asos’s app system to send an unauthorised push notification. That establishes when customers saw the notification, not when the attackers first gained access.

Later that day, Asos told shareholders through the London Stock Exchange that an “unauthorised third party” had sent the notification and that basic personal information, including names and contact details, might have been accessed. It subsequently emailed customers with similar wording, the BBC reported.

In its public customer-care notice, Asos says it is investigating unauthorised activity involving third-party services used for customer communications. It says it restricted access to notification platforms and is working with internal and external specialists and relevant authorities.

The notice tells customers to disregard the unauthorised notification and avoid its external link. It says the website and app remain available for shopping and does not ask customers to change their account passwords.

The public notice retained narrower language about possible exposure of basic contact information when checked on 8 October. Its publication and update times are unavailable; the fuller profile disclosure comes from the customer email reported by the BBC.

Why exposed details can make impersonation more convincing

“Please remain cautious of unexpected messages or calls claiming to be from Asos,” the company said in the email quoted by the BBC. It added: “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”

The National Cyber Security Centre’s standing data-breach guidance explains that criminals can use stolen personal information to make fraudulent emails and texts appear legitimate. Messages may impersonate the breached organisation and direct recipients to imitation websites that capture information entered there.

Exposed telephone numbers can also enable calls requesting sensitive information or access to a computer, the NCSC says. Its guidance recommends checking with an organisation through its official website or other established channels, rather than using links or contact details in incoming messages.

The NCSC also warns that criminals exploit publicity around breaches to target people whose information was not stolen. Receiving a suspicious message therefore does not itself prove that someone’s details were exposed. Such messages can arrive some time after a breach becomes public.

What remains unknown about the Asos breach

The initial access date, exact intrusion method and attacker identity have not been established in the reporting. Nor does the disclosure establish measured increases in phishing attacks or confirmed financial losses among Asos customers.

Asos says it will contact affected customers directly if required actions change and promises a further update once it confirms more information. Its public notice gives no deadline for that update or for completing the investigation.

Sources and context

AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.

About NewsJaws Desk

AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.