Asos Breach Exposes Customer Data, Cyber Attack Worse Than Initially Reported
Asos confirms major data breach exposing customer details. Hackers impersonated trusted contact to access personal info.
POLICY WIRE — London, United Kingdom — A cyber attack on Asos has exposed customer personal information, according to the online fashion retailer.
The incident came to light after customers received a mobile app notification on Tuesday that claimed “ASOS HACKED” and directed them to a Telegram account. The message suggested that hackers had gained access to sensitive data and threatened to release it.
📄 POLICY WIRE WHITEPAPER PUBLISHED: PAKISTAN’S NATIONAL SECURITY POLICY PRIORITIES
Following the alert, Asos confirmed a breach, revealing that an unauthorized party had impersonated a “trusted contact” to obtain login credentials for an employee account. This allowed the attacker to access customer data stored on third-party platforms linked to the company. While no payment card details or passwords were compromised, names, contact information, and shopping activity were reportedly accessed.
Experts warn that stolen personal data can be used for long-term scams, as cybercriminals can exploit details like names, contact info, and browsing history to craft convincing phishing attempts. Asos urged customers to remain vigilant against suspicious communications and advised using guest accounts when possible to reduce risks.
Reporting by Policy-Wire (PW)





