Asos Breach Is Wider Than the Company First Told Customers
Hackers hold detailed profiles of potentially millions of users, Asos has now acknowledged, after the BBC told the retailer the criminals had contacted it and that the breach went beyond the “basic contact details” first disclosed. Names, addresses, phone numbers, emails, customer numbers, dates of birth and site search histories were taken. No bank details or passwords.
The attackers obtained an employee’s login by impersonating a trusted contact — not a software flaw but a person persuaded to hand over access. Calling themselves Xuanyewen, they told the BBC they used a platform built on top of Snowflake to extract the data and claimed to have compromised the Snowflake instance; Snowflake has previously said its platform was not breached. Asos declined to answer questions about scale. The search histories are the part that should worry people, because they turn a list of names into a profile: someone who can tell you what you have been browsing, your date of birth and your address sounds exactly like a retailer with a genuine query. Asos has told customers to “remain cautious of unexpected messages or calls” and that it “will never ask you to share passwords, security codes or payment details through an unsolicited message or call”. One customer, who has used the site since 2019, put the wider risk well: “What I find particularly worrying is the possibility that stolen data can be used as a tool for future attacks, meaning the impact of a breach could extend well beyond the initial incident.” Asos says customers need take no action; security specialists advise changing passwords anyway.