Asos has confirmed that hackers accessed the personal information of millions of customers, including names, contact details and recent search histories, after breaching a third-party service provider by impersonating a trusted contact. The online fashion retailer said payment card details and passwords were not compromised, but its shares fell sharply when the attack became public on Tuesday.
Asos said on Thursday, after what it described as a detailed 48-hour investigation, that an unidentified third party had accessed basic personal information including customers' delivery and email addresses, names and phone numbers, as well as "certain non-personal account related information". This is understood to include shoppers' recent search histories on the app, with terms such as "glamorous wide fit" and "Asos petite" among the data accessed.
The incident first emerged on Tuesday, when app users received a push notification titled "Asos hacked" containing a link to the Telegram messaging service. News of the breach sent Asos shares down about 10%.
The retailer said the hackers gained access to a database held by one of its third-party service providers by impersonating a trusted contact to obtain an employee's login credentials, which were then used to access information on certain third-party platforms used by Asos. The affected platforms were immediately locked down, and a full investigation was launched with internal and external cyber experts. Asos said it is also working with law enforcement and regulatory authorities.
The company said its website and app continue to be safe to use and that customers do not need to take action, but it warned them to remain cautious of unexpected messages or calls claiming to be from Asos. "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call," it said.
The purported hackers, who call themselves the Xuanye Group, posted a message on their Telegram channel assuring customers that "payment information is not affected". Cyber experts said they had not heard of the group before and suggested the push notification could have been an attempt to gain wider attention.
Charles Allen, an analyst at Bloomberg Intelligence, said the hack might "temporarily cap the pace" of Asos's attempt to revive sales and profits after the Covid pandemic led to a boom followed by a sharp drop in trade. "The loss of customer trust could weigh on efforts to rebuild its client base," he said. Asos pledged to contact customers directly once its investigation is complete where additional information, support or action may be required.
Analysis
Why This Matters
- The breach exposed personal information of millions of customers, including home addresses and app search histories, leaving them vulnerable to targeted scams and phishing.
- It lands as Asos tries to rebuild sales and profits after a post-pandemic slump; lost customer confidence could slow that recovery.
- The attackers entered through a third-party provider, highlighting that retailers' security is only as strong as their suppliers' defences.
Background
Asos is one of the world's largest online-only fashion retailers. Publicly known details of the incident emerged on Tuesday, when app users received the "Asos hacked" notification directing them to Telegram, and the company confirmed the data access on Thursday after a 48-hour investigation. The attack followed a familiar pattern: social engineering to obtain an employee's login credentials, then use of those credentials to reach systems held by outside vendors. Asos's business boomed during the pandemic when online shopping surged, but trade dropped sharply as shoppers returned to stores, and the company has been working to revive sales.
Key Perspectives
Asos: Maintains that the affected platforms were locked down quickly, that its website and app remain safe to use, and that customers need take no action. It says it is cooperating with law enforcement and regulators and will contact customers directly where further support is needed.
Customers: Have been warned to watch for unsolicited messages or calls claiming to be from Asos. The company says it will never ask for passwords, security codes or payment details through such channels.
Analysts: Bloomberg Intelligence's Charles Allen says the incident could temporarily cap the pace of Asos's revival, with the loss of customer trust weighing on efforts to rebuild its client base.
Cyber experts: Had not previously encountered the Xuanye Group and suggested the mass notification may have been an attention-seeking move rather than part of a conventional extortion campaign.
What to Watch
- Whether Asos contacts affected customers directly as it has pledged, and whether its investigation identifies any additional data categories that were exposed.
- Whether the Xuanye Group resurfaces or any of the stolen data appears publicly.
- Asos's trading updates, which will show whether the breach has dented a sales recovery that was already under pressure.