Asos hackers took more personal details than first revealed, BBC finds

Asos hackers took more personal details than first revealed, BBC finds

Asos has informed its users that hackers have obtained detailed personal profiles of possibly millions of individuals who shop on the online platform. This announcement came after BBC News revealed they were contacted by cybercriminals claiming that the initial understanding of the breach—limited to “basic contact details”—understated its true extent.

The stolen information includes names, addresses, phone numbers, emails, and customer identification numbers. In addition, the attackers have accessed customers’ search histories on the site, revealing specific search terms such as “reclaimed vintage,” “glamorous wide fit,” and “Asos petite.” This kind of detailed data could enable fraudsters to carry out sophisticated phishing attempts via email or phone.

Asos sent emails to affected customers confirming that data profiles had been compromised, though it clarified that passwords and bank details were not part of the breach. Customers were cautioned to be wary of any unsolicited communication purportedly from Asos, with the company emphasizing that it would never request passwords, security codes, or payment details through unexpected messages or calls. However, Asos has not provided information regarding how many users were affected.

The breach first gained wide attention when hackers exploited Asos’s own app system to push a pop-up notification to potentially millions of users. Following this incident, Asos notified shareholders that an unauthorized third party was responsible, and that some basic personal information might have been exposed. Subsequently, the hackers reached out to the BBC and shared samples of the stolen data, demonstrating the breach’s severity. The BBC delayed publishing details to allow Asos time to alert its customers.

Asos is continuing to investigate the breach and has pledged to contact customers directly if additional information or action is necessary. The company explained that the hackers obtained access by impersonating a trusted contact to steal login credentials of an employee. Using these credentials, the attackers accessed an unnamed service from which they downloaded the customer data.

In the pop-up sent to users, the cybercriminals claimed to have compromised the “Snowflake instance.” Snowflake is a widely used data storage and analytics platform that has previously been targeted due to unauthorized access issues. The group behind the hack, calling themselves Xuanyewen, told the BBC they leveraged a platform called Simon AI—built on top of Snowflake—to access the data. While Asos confirmed that no action is currently required from customers, cybersecurity experts have advised changing passwords as a precaution and remaining vigilant for suspicious activity.

Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, cautioned users that although passwords were not stolen, they should be suspicious of unsolicited requests for password changes or sharing. He noted that scammers might reference the attack, use personal details to appear credible, and create a sense of urgency, such as threatening account lockdowns.

Despite the incident, Asos assured customers that its website and app remain safe to use. The company emphasized the trust customers place in them regarding personal information and stated that it has already implemented further security measures to strengthen protections moving forward

Read the full article from The BBC here: Read More