World

Asos Confirms Supplier Breach Exposed Millions of Shoppers' Data

Elena MarquezPublished 31m ago3 min readBased on 2 sources
Reading level
Asos Confirms Supplier Breach Exposed Millions of Shoppers' Data
Photo by Artem Beliaikin on Unsplash

Asos has confirmed that an outside intruder accessed basic personal details for millions of customers, including names, delivery addresses, email addresses and phone numbers, plus recent search histories. The Guardian

The update came on Thursday 8 October after a detailed 48-hour investigation, two days after the first public signs of intrusion. Asos said payment card details and passwords were not accessed in the cyber attack.

Investigators traced entry to a database held by one of Asos's third-party service providers, an outside firm that handles work for Asos. Hackers obtained an employee's login credentials by impersonating a trusted contact. The target was the person, not the software. Asos reported no compromise of its payment or password systems.

The company described a second category taken as certain non-personal account-related information, understood to include recent search history on the app. Search terms including "glamorous wide fit" and "Asos petite" were among the data accessed. Contact details were taken alongside records of normal browsing.

The incident emerged on Tuesday 6 October after app users received a notification titled "Asos hacked" with a link to the Telegram messaging service. The operators of that Telegram channel call themselves the Xuanye Group.

Asos said its website and app continued to be safe to use and that customers did not need to take action.

ASOS shares fell 10% on Tuesday after the retailer warned that some customer information may have been accessed. Reuters

The broader context here is how entry point, data types and disclosure fit together for retail platforms. Entry through a provider system after impersonation puts focus on access rules beyond the main perimeter, including vendor accounts, limits on permissions and checks on trusted contacts. Payment and password systems were untouched as described, which narrows but does not remove the exposure.

Looking at what this means for customers and markets, the pairing is instructive. Names, addresses, emails and phone numbers allow contact. Recent searches add context for that contact. Even without financial data, that combination can support convincing lures by text, email or phone. The market fall on Tuesday came before Thursday's fuller account, a sequence that explains the speed of repricing around uncertainty.

Questions that follow concern assurance rather than attribution. How the provider account was validated, how widely search and contact data were stored together, and how push alerts can be protected from misuse for external links will matter for restoring confidence. Statements that core services are safe to use sit alongside continued scrutiny of supply chains where much customer data now resides.