Technology and Scienceupdated 1h ago2 min read
Asos Says Hackers Accessed Names, Addresses, Phone Numbers, Emails, Customer Numbers
Hackers accessed names, addresses, phone numbers, emails, and customer numbers. Rogue in-app push notification claimed hacking and warned of data leakage.

Hackers expand data scope
ASOS told customers that hackers were in possession of detailed profiles of potentially millions of online store users, and the company said the breach went beyond the "basic contact details" it had previously disclosed. BBC News reported that cyber criminals contacted the retailer saying this week's breach went beyond the "basic contact details" Asos previously said might have been accessed, and Asos then confirmed that names, addresses, phone numbers, emails and customer numbers were in the hands of cyber criminals.
“Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.”
Asos also said the hackers had access to "certain non-personal account related information" and that it did not believe payment card information or account passwords were accessed. Asos warned customers to "Please remain cautious of unexpected messages or calls claiming to be from Asos," and the retailer said it would "never ask you to share passwords, security codes or payment details through an unsolicited message or call."

Social engineering and access
Asos said it discovered an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log in credentials, and the company said those credentials were then used to access information on certain third-party platforms used by Asos. Hackers gained access to a database of one of Asos's third-party service providers by impersonating a "trusted contact" to gain access to one of its employee's accounts.
Asos locked down the affected platforms immediately, and Asos told customers that its website and app were safe to use throughout and remain safe to use. The Guardian described the breach as including customers' recent search histories, with terms typed in by customers such as “glamorous wide fit” and “Asos petite” in the data accessed in the cyber-attack.

Threats, regulators, and risk
Hackers used Asos's app system to send a pop up notification titled “Asos hacked,” and the message directed recipients toward a Telegram channel controlled by the Xuanye Group. Cyber criminals contacted the BBC sharing a sample of the stolen data, and Asos later told shareholders via the London Stock Exchange that the pop up was sent by an "unauthorised third party".
The Guardian said the Telegram channel message included a warning that “payment information is not affected,” while Asos told customers it did not believe payment-card information or account passwords were impacted. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, warned that "Expect scammers to mention the attack, use your personal details to seem genuine, and create urgency" and Asos said it was working with relevant law enforcement and regulatory authorities.