Asos has disclosed that hackers obtained far more customer data than initially disclosed following this week's breach of the online fashion retailer.
The company confirmed that names, addresses, phone numbers, email addresses, customer numbers and dates of birth are now in the hands of criminals. Asos previously said only "basic contact details" might have been accessed. The BBC reported Wednesday that cyber criminals claiming to be part of a group called Xuanyewen contacted the news organization with samples of stolen data showing the expanded scope of the breach.
The hackers also accessed records of customer searches on Asos's platform, meaning criminals can see what items individual users have browsed. One customer told the BBC she found it "very unsettling" that attackers now possess these personal details about her and her shopping history dating back to 2019.
Asos confirmed in a new email to customers that bank details and passwords were not accessed. However, security experts warn that stolen personal information creates vulnerability to follow-up attacks. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, cautioned that scammers may use the breached personal details to craft convincing phishing emails or impersonation calls, and may claim urgency to pressure victims into changing passwords or sharing security codes.
Asos said hackers gained entry by impersonating a trusted contact to obtain an employee's login credentials to an unnamed service. Using that access, criminals downloaded customer data. The hackers claimed in their notification to users that they had "compromised the Snowflake instance," referring to a cloud data storage company whose platform has experienced unauthorized access incidents in the past.
The company said its website and app remain safe to use and encouraged customers to remain cautious of unsolicited messages or calls claiming to be from Asos. Security researchers advise changing passwords as a precaution and watching for suspicious account activity. Asos said it is continuing to investigate the breach and will contact customers where additional support may be needed.
