Asos has informed customers that cybercriminals possess detailed profiles of potentially millions of users, significantly expanding the scope of the recent security incident. The retailer issued this update after BBC News reported that the attackers claimed access to data far beyond the “basic contact details” initially disclosed.
According to the investigation, the stolen information includes names, home addresses, phone numbers, email addresses, customer numbers, and dates of birth. The hackers also obtained records of search terms used on the platform, such as “reclaimed vintage,” “glamorous wide fit,” and “Asos petite.” One customer, Harriet, who has used the service since 2019, expressed concern that this granular data could facilitate future targeted attacks.
Expanded Scope of Stolen Information
The initial notification sent to shareholders via the London Stock Exchange stated that only basic personal information might have been accessed. However, on Wednesday evening, the cybercriminals, identifying themselves as Xuanyewen, contacted the BBC with a sample of the stolen data. This evidence showed that the breach extended to comprehensive user profiles.
Asos confirmed in an email to customers that data profiles were taken but emphasized that no bank details or passwords were compromised. The company advised shoppers to remain cautious of unexpected messages or calls claiming to be from the brand. “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call,” the statement read.
Security experts warn that the availability of personal details increases the risk of impersonation scams. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, noted that scammers are likely to use stolen information to create convincing phishing emails or phone calls. He advised users to be highly suspicious of unsolicited requests to change passwords or share security codes.
Method of Access and Security Response
The breach gained global attention when hackers used Asos’s own app system to send a pop-up notification to millions of users. The notification claimed the attackers had compromised a Snowflake instance. Snowflake is a popular data storage and analysis platform. The hackers stated they used a platform called Simon AI, which is built natively on top of Snowflake, to gain access to the data.
Asos explained that the intruders gained access to an employee account by impersonating a trusted contact to obtain login credentials. With access to an unnamed service, the hackers were able to download the customer data. Snowflake has previously stated that its core platform was not breached, while Simon AI has been contacted for comment.
Asos stated that its website and app are safe to use and that it has taken additional steps to strengthen security controls. The company added that it is still investigating the incident and will contact customers directly where additional support or action may be required.
Source: BBC

