ASOS confirms customer data exposure after cyber incident

ASOS confirms customer data exposure after cyber incident

ASOS confirms customer information was accessed through third-party communication platforms. Its latest disclosure follows the earlier unauthorised app notification and identifies an employee credential compromise, while excluding payment cards and passwords.


Online fashion retailer ASOS has confirmed that attackers accessed some customer personal information through third-party platforms, adding a material finding to its earlier investigation of unauthorised messages sent through its shopping app.

In an update on 8 October, the company said an unauthorised party obtained an employee’s login credentials by impersonating a trusted contact. The credentials were then used to access information held on external platforms used by the retailer to communicate with customers.

ASOS identified names and contact details among the information accessed, alongside certain non-personal account-related information. It said payment card information and account passwords were not accessed, according to its findings at the time of the announcement. Those distinctions are important because the risk associated with a breach depends on which records were exposed.

Customers had received an unauthorised push notification on 6 October, prompting the retailer to restrict access to affected communication platforms and investigate. The initial account concerned the suspicious notification and possible unauthorised activity; the latest disclosure confirms exposure of specified information and provides a clearer explanation of the entry method.

The retailer said the affected platforms were locked down, while its website and app remained available for ordinary shopping. It has been working with internal and external specialists, law enforcement and relevant authorities to determine the full scope of the incident.

The described method is a form of social engineering, in which a person is deceived into granting access or disclosing credentials. Such attacks exploit trust and organisational processes rather than necessarily requiring attackers to defeat the underlying technology of a service provider.

Retailers commonly depend on specialist external systems for messaging, customer engagement, analytics and support. These arrangements can reduce development costs and simplify operations, but access permissions and data sharing extend responsibility beyond the main ecommerce platform.

A compromised employee account can create exposure where permissions allow access to records across a connected service. The practical response therefore involves examining what the account could reach, determining which information was retrieved and reviewing controls intended to prevent similar access.

The public record does not establish that the entire ASOS customer database was downloaded or that every customer was affected. Earlier messages circulated by the attackers referred to a named technology provider, but their allegations should not be treated as proof that the provider’s core platform was compromised.

Even relatively basic contact information can create risks for customers. Names, addresses, email accounts or telephone numbers may help criminals construct convincing messages that appear to come from a retailer. The absence of payment card and password exposure reduces particular risks but does not eliminate the potential for later impersonation attempts.

ASOS has advised customers to be cautious about unexpected communications. Its earlier customer guidance instructed recipients not to engage with links in the unauthorised notification and said the company was not routinely requiring password changes as an immediate response.

For a business dependent on digital retail, incident handling is also an operational matter. Staff must coordinate technical containment, customer service responses, data protection assessments and clear communications while continuing to process orders and maintain service availability.

The retailer has not quantified the cost of the incident or confirmed any lasting effect on sales. Insurance arrangements or the movement of its share price do not establish the eventual financial consequences, which will depend on investigative findings, remediation work and customer response.

Under UK data protection requirements, organisations must assess whether a personal data breach requires regulator notification or direct communication to affected individuals. The engagement of authorities is not itself evidence of a legal violation, and conclusions about responsibility should await more complete findings.

The confirmed access to personal information is the reason for a separate follow-up after the 6 October report. The remaining issues are the number of affected individuals, the full set of records involved and whether further safeguards are required across the connected platforms. Those details have not all been established publicly.

—



  • UKAEA supports General Fusion plasma heating milestone

    UKAEA supports General Fusion plasma heating milestone

    UKAEA and General Fusion report a significant plasma heating milestone. Electron temperatures exceeded 12 million°C in the LM26 experiment, although commercial electricity generation remains a separate and substantially harder objective.


  • UK opens Kyiv business centre for industrial partnerships

    UK opens Kyiv business centre for industrial partnerships

    Britain has opened a permanent business centre in Kyiv today. The facility supports industrial partnerships and potential co-production between UK companies and Ukrainian organisations, especially SMEs.


  • ASOS confirms customer data exposure after cyber incident

    ASOS confirms customer data exposure after cyber incident

    ASOS confirms customer information was accessed through third-party communication platforms. Its latest disclosure follows the earlier unauthorised app notification and identifies an employee credential compromise, while excluding payment cards and passwords.