Asos Hack Reveals Sensitive User Data Beyond Contact Details

Published: October 8, 2026, 6:49 pm

Asos has confirmed that hackers successfully accessed detailed profiles belonging to potentially millions of its customers. The retailer issued an updated statement following inquiries from the media, which revealed that the recent cyberattack compromised significantly more data than the “basic contact details” the company had initially reported. According to it issued the update after told the retailer it had been contacted by cyber criminals who, This week’s breach went beyond the “basic contact details” Asos previously said might have been accessed. On Wednesday evening the cyber criminals responsible contacted sharing a sample of the stolen data which showed the true extent of the hack.

The stolen information includes full names, email addresses, phone numbers, home addresses, and unique customer identification numbers. Furthermore, the breach exposed personal browsing habits, including specific product search terms such as “reclaimed vintage,” “Asos petite,” and “glamorous wide fit.” These detailed datasets could allow malicious actors to launch sophisticated phishing campaigns or impersonation attempts against the company’s user base. The risk to individuals is now higher and customers are being warned about potential impersonation scams. The company then sent an email to customers with similar wording.

This incident first gained widespread attention on Tuesday when attackers utilized the retailer’s own application infrastructure to push a pop-up notification to users. The company later informed shareholders via the London Stock Exchange that an unauthorized party had gained access to an employee account by impersonating a trusted contact. This breach of credentials allowed the intruders to download customer data from an unnamed service.

The hackers, who have identified themselves as a group called Xuanyewen, claimed in a message to the media that they accessed the information via Simon AI, a platform built on top of the data storage service Snowflake. While Snowflake previously stated its own platform had not been breached, Simon AI has been approached for comment regarding the incident. Snowflake is a popular data storage and analysis company whose customers have been breached in the past due to unauthorised log ins.

Despite the extent of the data theft, Asos maintains that no passwords or banking details were compromised. In its official communication to customers, the company stated that it is currently investigating the full scale of the breach and will reach out directly to those requiring additional support. The retailer insists that its app and website remain secure, noting that it has already implemented enhanced security measures. So too are the searches customers have made on the website. We take that responsibility seriously and have already taken additional steps to further strengthen security controls,” it said.

Security experts urge users to remain hyper-vigilant. Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, warned that scammers are likely to use the stolen personal details to build trust and create artificial urgency. “Passwords have not been stolen, so be highly suspicious of any unsolicited text or email asking you to change or share yours,” Dearing cautioned, adding that attackers may threaten to lock accounts within 24 hours to force quick action.

Asos has explicitly advised customers to be cautious of any unexpected communications claiming to be from the brand. The company reiterated that it will never request passwords, security codes, or payment information through unsolicited messages or calls. While the company stated that customers do not need to take immediate action, experts recommend staying alert for any suspicious account activity as a general precaution.