Online fashion giant ASOS has confirmed that hackers accessed a significantly wider selection of personal data than initially disclosed by the retailer.
Following a 48-hour internal investigation, the retailer updated customers to reveal that the unauthorised actors managed to extract detailed user profiles for potentially millions of shoppers.
While and uncompromised, the compromised database includes full names, home addresses, phone numbers, email addresses and unique customer identification numbers.
Crucially, the breach also exposed granular personal insights, including customers’ recent onsite search histories. Specific phrases typed into the app, ranging from brand queries to clothing preferences like “reclaimed vintage” and “Asos petite”, were captured in the leak.
Security experts warn that combining these search metrics with personal contact data drastically increases the risk of sophisticated, highly targeted phishing emails and fraudulent phone scams.
The security lapse occurred after hackers gained unauthorised access to an ASOS employee account by impersonating a trusted contact to harvest login credentials. Those credentials were then exploited to infiltrate third-party data platforms utilised by the company.
The incident first came to light when the cyber criminals executed a brazen extortion plot, hijacking ASOS’s native app notification system to blast a directly to millions of consumer devices.
ASOS stated that the affected platforms were immediately locked down and that law enforcement and regulatory authorities have been notified.
Although the company insists its website and app remain safe to use and that customers do not need to take immediate account action, security professionals advise shoppers to exercise heightened vigilance against unsolicited messages or impersonation attempts referencing the retailer.
Discover more from Tech Digest
Subscribe to get the latest posts sent to your email.