ASOS confirmed an unauthorised party accessed customer names, contact details, and shopping searches after an employee was tricked into sharing login credentials. The retailer said it secured the affected platforms on Tuesday. While payment details and passwords remain safe, the company urged shoppers to watch for unexpected communications and scams.

ASOS said the attacker posed as a trusted contact and tricked an employee into sharing their login details. The attacker then used those credentials to access company information stored on third-party platforms. ASOS said it had secured the affected platforms to block any further unauthorized access.

A shopping notification became a warning nobody expected. On Tuesday, ASOS app users received a message titled "Asos hacked", directing them to a Telegram channel. Two days later, the retailer confirmed that an unauthorised party had accessed customer information. Names and contact details were among the affected data. Shopping searches were also accessed, according to reporting by the BBC and The Guardian.

ASOS says payment card details and passwords were not accessed. Its latest update nevertheless leaves shoppers facing an uncomfortable question: what could someone do with the information that was exposed?

What Customer Information Was Accessed in the ASOS Hack?Following a 48-hour investigation, ASOS said the breach involved basic personal information. Delivery addresses and email addresses were included. Customer names and phone numbers were also accessed.

The retailer additionally referred to non-personal account information. The Guardian reported that this included recent searches within the app, citing earlier BBC reporting.

You Might Also Like:

Jeff Bezos says AI could bring a 3 day work week, so why is Amazon cutting jobs?

Search terms such as "glamorous wide fit" and "Asos petite" appeared in the accessed data. An exact total of affected customers was not provided in the report.

How Did the Hackers Gain Access?ASOS said an attacker impersonated a trusted contact to obtain an employee's login credentials. Those credentials were then used to access information on third-party platforms used by the company.

The company said affected platforms were locked down to prevent further access. Specialists and cybersecurity experts began investigating.

ASOS said it was working with law enforcement and regulatory authorities. The findings point to stolen credentials as the entry route described by the retailer.

Are ASOS Passwords and Payment Details Safe?ASOS said passwords and payment card information were not accessed. It also said its website and app remained safe to use. The retailer told customers they did not need to take action. Security controls had been introduced, it said.

However, keeping card information protected does not erase the exposure of contact details. Customers should pay attention to the company's separate warning about unexpected communications.

What Should ASOS Customers Watch For Now?ASOS urged shoppers to be cautious about unsolicited messages or calls claiming to represent the retailer. It said it would never request passwords, security codes or payment details through such contact.

The company pledged to contact customers where support or action was needed after its investigation.

A Telegram channel linked from Tuesday's notification identified its operators as the Xuanye Group. Its claimed identity has not been independently established in the supplied reporting.

For shoppers, the concern is recognising genuine communication. A familiar brand name on a message is not, by itself, proof that the sender can be trusted.

FAQs

What was accessed in the ASOS hack?Personal contact information and, reportedly, recent app searches.

Were payment details accessed?ASOS says payment card information was not accessed.