Asos has disclosed that hackers obtained far more personal data than the retailer initially revealed following this week's breach. The company told customers that criminals now possess detailed profiles including names, addresses, phone numbers, emails, customer account numbers and dates of birth for potentially millions of users.
The BBC learned of the expanded breach scope after cyber criminals claiming responsibility contacted the news organization and shared sample data. Asos had first disclosed to shareholders and customers on Tuesday that only "basic contact details" might have been accessed. The retailer has since confirmed the hackers also obtained customer search histories, such as product queries for "reclaimed vintage," "glamorous wide fit" and "Asos petite."
The criminals accessed customer data through a compromised employee account. Asos stated that hackers obtained login credentials by impersonating a trusted contact. Using those credentials, they downloaded customer information from an unnamed service. The pop-up notification sent to millions of Asos users on Tuesday claimed the breach involved "compromised the Snowflake instance." Snowflake is a data storage platform. The hackers, who identify themselves as Xuanyewen, told the BBC they used Simon AI, a platform built on Snowflake, to gain access.
Asos confirmed that bank details and passwords were not accessed. The company said it is investigating and will contact customers where additional information, support or action may be required. Snowflake previously said its platform had not been breached.
Security experts warn that criminals can use the stolen personal details to craft convincing phishing attacks and impersonation scams. One customer told the BBC that knowing the hackers hold such information is "very unsettling." Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, advised users to remain suspicious of unsolicited emails or texts requesting password changes, as scammers may reference the attack and use personal details to appear legitimate.
Asos advised customers not to take action but said its website and app remain safe. The retailer urged customers to remain cautious of unexpected messages claiming to be from Asos and reiterated it will never request passwords, security codes or payment details through unsolicited contact.
