Asos hackers took more personal details than first revealed, BBC finds
-
Published
Asos has told its customers that hackers are in possession of detailed profiles of potentially millions of the online store’s users.
It issued the update after BBC News told the retailer it had been contacted by cyber criminals who said this week’s breach went beyond the “basic contact details” Asos previously said might have been accessed.
Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.
So too are the searches customers have made on the website. Terms like “reclaimed vintage”, “glamorous wide fit” and “Asos petite” are visible in the data.
With this information, scammers may be able to craft potent phishing attack emails or phone calls.
The risk to individuals is now higher and customers are being warned about potential impersonation scams.
In its email to customers, Asos confirmed data profiles were taken but said no bank details or passwords were accessed.
“Please remain cautious of unexpected messages or calls claiming to be from Asos,” it said.
“We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
The company did not respond to questions about the scale of the breach.
The high profile hack made global headlines on Tuesday when cyber criminals used Asos’s own app system to send a pop up notification to potentially millions of people.
Later that day the firm confirmed to shareholders via the London Stock Exchange that the pop up was sent by an “unauthorised third party” and “basic personal information including name and contact details may have been accessed.”
The company then sent an email to customers with similar wording.
On Wednesday evening the cyber criminals responsible contacted the BBC sharing a sample of the stolen data which showed the true extent of the hack.
The BBC held off publishing this article to allow Asos to contact its customers first.
‘Impersonating a contact’
Asos said it is still investigating how the hack happened.
It told customers hackers “gained access to an Asos employee account by impersonating a trusted contact to obtain log in credentials”.
With that log in to an unnamed service, the hackers were able to download the customer data.
In the pop up notification send to customers by the hackers, they claimed they had “compromised the Snowflake instance”.
Snowflake is a popular data storage and analysis company whose customers have been breached in the past due to unauthorised log ins.
The cyber criminals, calling themselves Xuanyewen, claimed to the BBC they used a platform which is built natively on top of Snowflake – called Simon AI – to gain access to the data.
Simon AI has been contacted for comment. Snowflake previously said its platform had not been breached.
Asos said customers are not being asked to take any action.
But cyber security experts have warned users to change passwords as a precaution and be on alert for suspicious activity.
Asos said its website and app are safe to use and “we know our customers trust us with their information”.
“We take that responsibility seriously and have already taken additional steps to further strengthen security controls,” it said.
-
Asos confirms hackers sent ‘unauthorised’ notification to app users
-
Published1 day ago
-
-
What can I do to protect myself after ‘Asos hacked’ message?
-
Published1 day ago
-

Sign up for our Tech Decoded newsletter to follow the world’s top tech stories and trends. Outside the UK? Sign up here.


