ASOS Confirms Customer Data Breach, No Financial Impact

ASOS has acknowledged that customer data was exposed via third-party services after hackers stole an employee’s credentials. The breach did not expose payment-card data or account passwords, the company stated.
A statement released to customers on October 8 revealed the attacker gained entry by posing as a verified contact. ASOS clarified that only authorized personnel could have initiated this access.
ASOS emphasized that financial and login credentials remained secure, and its digital platforms continued operating normally.
The BBC disclosed that leaked files, provided by individuals claiming responsibility, contained full customer profiles for what could affect millions of users. The sample included home addresses, phone numbers, email addresses, customer IDs, and browsing history from ASOS’s platform.
The broadcaster noted ASOS’s statement came after being informed of the leaked data. Experts warn such details could enable fraudsters to craft more convincing phishing attempts.
Read Also: Argos boosts beauty product range
ASOS promptly restricted access to compromised systems and is collaborating with internal security teams, external cyber specialists, law enforcement, and regulators to reinforce protections.
The breach surfaced on October 6 when users received an unsolicited alert in the ASOS app falsely claiming a system compromise. The company’s first response indicated that customer names and contact details may have been viewed.
While ASOS assured customers no account changes were necessary, it cautioned against responding to unsolicited outreach purporting to represent the brand.
Anwen Haynes, Chief Marketing Officer at cybersecurity firm Quod Orbis, observed: “The primary danger lies in treating the website as the sole attack vector. Retailers now interact with a complex network of third-party tools for marketing, analytics, payments, data storage, and more, each capable of introducing vulnerabilities or creating new entry points.”
She continued: “Companies should leverage this event to conduct a full audit of their digital infrastructure beyond just their primary site. They must identify every external service with access to customer, employee, or operational data, evaluate the permissions granted, and verify that safeguards are actively functioning.”