Asos Hackers Stole More Personal Data Than Revealed
BBC discovers Asos hackers obtained detailed user profiles including names, addresses, and phone numbers, raising scam risks.

Stock photo for illustration only, not from the actual event
- Hackers accessed detailed personal data profiles of millions of Asos online store users.
- Stolen information includes names, home addresses, phone numbers, emails, and customer numbers.
- Asos confirmed that passwords and banking details remain uncompromised.
- Cyber criminals claimed they used Simon AI built on Snowflake to breach the system.
An investigation by BBC Business has revealed that hackers who targeted the online fashion retailer Asos obtained far more detailed personal data of users than the company initially disclosed. Cyber criminals are now in possession of deep customer profiles belonging potentially to millions of shoppers, encompassing sensitive details such as full names, physical addresses, telephone numbers, email addresses, and unique customer identification numbers.
With this specific information in the hands of malicious actors, security analysts warn that scammers could orchestrate highly convincing phishing emails or fraudulent phone calls. Because the attackers possess legitimate personal data, victims are at a significantly higher risk of targeted impersonation scams. In an email dispatched to affected users, Asos verified that data profiles were extracted during the breach, though it firmly maintained that passwords and financial credentials such as bank details were not accessed.

Stock photo for illustration only, not from the actual event
The high-profile cyber attack made global headlines when the perpetrators utilized Asos's own official application infrastructure to trigger a pop-up notification sent directly to potentially millions of users. The company subsequently followed up with formal email notifications to its customer base. By Wednesday evening, the threat actors identifying themselves as Xuanyewen reached out to the BBC, providing a sample of the pilfered database to demonstrate the true magnitude of the security incident.
The ability of hackers to hijack an official corporate app to broadcast messages directly to consumers highlights an alarming trend in modern cyber attacks. Beyond simple data theft, threat actors increasingly leverage a company's own communication channels to maximize psychological leverage. This incident underscores that employee credential compromise remains a critical vulnerability, proving that robust perimeter security alone is insufficient if internal access controls are bypassed through social engineering.
Asos explained during its ongoing investigation that the breach originated when hackers compromised an employee account by impersonating a trusted contact to harvest login credentials. Utilizing this unauthorized access to an internal service, the attackers downloaded the customer repository. The cyber criminals specifically claimed to the BBC that they leveraged a platform natively built on top of the data cloud company Snowflake, known as Simon AI, to facilitate the data extraction process.
While Asos has stated that customers do not need to take immediate action at this time, cybersecurity experts strongly advise users to remain vigilant and alter their passwords as a precautionary measure. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, warned that scammers are likely to weaponize the stolen personal details to manufacture urgency and trick victims into compliance. Asos assures users that its primary platform and app remain secure and that additional security controls have already been deployed.
Source: BBC Business
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment