sözaltı news World
World
EN AZ
Asos customers’ names, search histories and contact details accessed in hack, says retailer

Asos customers’ names, search histories and contact details accessed in hack, says retailer

theguardian.com 08.10.2026 13:44 7 views
Hackers gained access to millions of users’ personal data, but not card details or passwords, Asos saysBusiness live – live updatesAsos hackers gained access to millions of customers’ recent search histories as well as n

Asos hackers gained access to millions of customers’ recent search histories as well as names, addresses and phone numbers, the online fashion retailer has revealed. Terms typed in by customers such as “glamorous wide fit” and “Asos petite” were in the data accessed in the cyber attack, which emerged on Tuesday after app users received a notification titled “Asos hacked” with a link to the Telegram messaging service. After carrying out a “detailed, 48-hour investigation” into the incident, Asos confirmed on Thursday that basic personal information had been accessed by an unidentified third party.

This included customers’ delivery and email addresses, names and phone numbers. Hackers gained access to a database of one of Asos’s third-party service providers by impersonating a “trusted contact” to gain access to one of its employee’s accounts, the retailer said. Asos said they had also gained access to “certain non-personal account related information”, which are understood to include shoppers’ recent search history on the app, as first reported by the BBC which was contacted by the hackers.

Payment card details or passwords had not been accessed, the retailer added. It said in a message to customers on Thursday: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos.

We are also working with the relevant law enforcement and regulatory authorities.” It said the Asos website and app continued to be safe to use, that customers did not need to take action and that it had “already taken additional steps to further strengthen security controls”. However, the company warned: “Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.” Charles Allen, an analyst at Bloomberg Intelligence, said the hack might “temporarily cap the pace” of Asos’s attempt to revive sales and profits, after the Covid pandemic led to a period of boom followed by a sharp drop in trade.

Asos pledged to contact customers directly once its investigation was complete and “where we believe additional information, support or action may be required”. The Telegram channel operated by the purported hackers, who have named themselves the Xuanye Group, to which users were directed on Tuesday carried a message assuring Asos customers that “payment information is not affected”. Cyber experts said that they had not heard of the group before and that the push notification could have been an attempt to gain wider attention.

Extract — continue reading at the source.

Read full story