Asos warns that hackers may have access to detailed customer profiles, including names, addresses, phone numbers, emails, customer numbers and site search history.
The breach appears to extend beyond previously disclosed basic contact details, increasing risk of targeted phishing and impersonation.
Asos says no bank details or passwords were accessed in the breach, but the data set could still be used for scams.
Consumers should be cautious of unexpected messages and verify any requests for information claiming to be from Asos.
Quick read · 1 min
Asos says hackers now hold detailed customer profiles, including names, addresses, phone numbers, emails and site search history. No bank details were accessed, but the data could fuel targeted phishing. To protect yourself, watch for suspicious messages, verify with the official Asos app or site, enable two-factor authentication, and review your account security regularly. Asos will investigate and share updates as they become available.
The breach at online retailer Asos has taken a troubling turn. The company says hackers now possess detailed customer profiles that go beyond basic contact details. Information reported by customers includes names, addresses, phone numbers, emails, customer numbers and even the searches people carried out on the site. The update comes after the retailer was first widely publicized for a pop-up notification sent through its app, which the company later described as coming from an unauthorized third party.
In a note to customers, Asos emphasized that while basic personal information was accessed, no bank details or passwords were compromised. Still, the expanded data set raises risk of targeted scams, impersonation attempts, and phishing emails that could appear more convincing because they cite real customer information.
01
What was exposed in the breach?
According to Asos, the data includes names, addresses, phone numbers, email addresses and customer numbers. It also includes the searches users made on the platform. Hackers could leverage this to craft more believable phishing messages or phone calls that seem tailored to you.
02
Why this matters to you
For everyday shoppers, this isn’t just a list of numbers. It points to how cyber criminals can impersonate real customers in scams. If a scammer knows your recent searches, they might pretend to be a familiar retailer or claim they need to verify an order. Even without payment data, the risk of social engineering remains high.
03
What changed about the breach
Earlier this week, the BBC reported that hackers claimed the breach went beyond basic contact details. Asos confirmed that statement and said the data profiles in possession now include more granular information. The company did not share a scale for how many accounts are affected, and it has not provided a new breach tally since the initial disclosures.
04
What this means for your privacy and money
The immediate risk is phishing and impersonation scams that are harder to spot. If someone learns your name, address and recent searches, they could tailor messages to look more legitimate. It’s not a sign that your money was stolen yet, but it’s a reminder to treat unsolicited messages with caution and to verify requests independently.
– Be skeptical of messages that reference your Asos account. Do not click links or share codes from unsolicited messages. – If you get a message claiming to be from Asos, contact the retailer using a trusted method (the official app, or their verified website) to verify its authenticity. – Consider enabling two-factor authentication if you haven’t already, and monitor your account for unusual activity. – Review your account details and update security questions if you notice anything odd.
06
What happens next
Asos says it will continue to investigate and will inform customers if more information becomes available. For now, shoppers should stay cautious and expect more updates as the investigation unfolds.
07
Quick answers
Will I be charged or have my bank data stolen?
No bank details or passwords were accessed according to Asos, but you should still treat any unexpected message with care.
How can I protect myself right away?
Watch for phishing attempts, update your security details, and use two-factor authentication where available.
A UPS shipment carrying sensitive F-35 cockpit canopy and weapons-bay door components was allegedly rerouted through Hong Kong after an employee missed an ITAR alert, raising questions about secure handling of military tech.
Raheim Hamilton, co-creator of Empire Market, gets 40-year prison term for running a platform that facilitated hundreds of millions in illegal drug sales and other crimes.
In Kakuma, refugees use AI tools to research and translate, but pay is inconsistent and transparency is uneven. Here’s what it means for ordinary workers.
3 min read
We use cookies to understand how readers use Talk With Tech, so we can make it better. Is that OK? Privacy policy