ASOS hack exposed more than contact details; even your shopping searches were accessed: What should customers do?
ASOS said the attacker posed as a trusted contact and tricked an employee into sharing their login details. The attacker then used those credentials to access company information stored on third-party platforms. ASOS said it had secured the affect...

ASOS hack exposed more than contact details; even your shopping searches were accessed: What should customers do? (Image: Reuters)
ASOS says payment card details and passwords were not accessed. Its latest update nevertheless leaves shoppers facing an uncomfortable question: what could someone do with the information that was exposed?
What Customer Information Was Accessed in the ASOS Hack?
Following a 48-hour investigation, ASOS said the breach involved basic personal information. Delivery addresses and email addresses were included. Customer names and phone numbers were also accessed.The retailer additionally referred to non-personal account information. The Guardian reported that this included recent searches within the app, citing earlier BBC reporting.
Search terms such as “glamorous wide fit” and “Asos petite” appeared in the accessed data. An exact total of affected customers was not provided in the report.
How Did the Hackers Gain Access?
ASOS said an attacker impersonated a trusted contact to obtain an employee’s login credentials. Those credentials were then used to access information on third-party platforms used by the company.The company said affected platforms were locked down to prevent further access. Specialists and cybersecurity experts began investigating.
ASOS said it was working with law enforcement and regulatory authorities. The findings point to stolen credentials as the entry route described by the retailer.
Are ASOS Passwords and Payment Details Safe?
ASOS said passwords and payment card information were not accessed. It also said its website and app remained safe to use. The retailer told customers they did not need to take action. Security controls had been introduced, it said.What Should ASOS Customers Watch For Now?
ASOS urged shoppers to be cautious about unsolicited messages or calls claiming to represent the retailer. It said it would never request passwords, security codes or payment details through such contact.A Telegram channel linked from Tuesday’s notification identified its operators as the Xuanye Group. Its claimed identity has not been independently established in the supplied reporting.
For shoppers, the concern is recognising genuine communication. A familiar brand name on a message is not, by itself, proof that the sender can be trusted.
FAQs
What was accessed in the ASOS hack?
Personal contact information and, reportedly, recent app searches.Were payment details accessed?
ASOS says payment card information was not accessed.The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.
The Economic Times News App for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.