Online fashion retailer Asos has acknowledged that hackers obtained detailed profiles on potentially millions of its users, far more than the “basic contact details” it initially said may have been accessed in an attack that first came to light on Tuesday, 6 October.
The data accessed includes names, addresses, phone numbers, email addresses, customer numbers and dates of birth, as well as searches made through the service.
Terms such as “reclaimed vintage”, “glamorous wide fit” and “Asos petite” were visible in samples of data that the attackers reportedly showed to the BBC.
Stolen login
Asos issued an updated statement on the hack on 8 October, after being contacted by the BBC.
It said an unauthorised third party gained access to an Asos employee account by impersonating a trusted contact to obtain the employee’s login credentials.
Hackers often impersonate trusted personnel from within a company, such as a technical support representative, in order to obtain security details.
“Those credentials were then used to access information on certain third-party platforms used by Asos,” the company said.
In a pop-up app notification sent to Asos customers’ devices around the world on the morning of 6 October, the hackers claimed to have stolen data from an Asos Snowflake instance, a platform used to store and analyse customer data.
Fraud warning
The hackers told the BBC they accessed the data via Simon AI, a marketing platform integrated with Snowflake.
Snowflake has in the past been linked to major breaches of customer data, including incidents involving Ticketmaster and Santander.
Asos said its service remains safe to use, customers do not need to take action, and that it has strengthened security controls.
It urged customers to be wary of “unexpected messages or calls” which may be efforts to use the stolen data to impersonate the company.