The Scale of the Intrusion
Online fashion giant Asos has warned customers that a recent cyber attack was far more serious than initially disclosed. Hackers now hold detailed profiles belonging to potentially millions of users.
This update came after BBC News contacted the retailer. Cyber criminals had reached out to the broadcaster, sharing samples of the stolen data to prove they took much more than the “basic contact details” Asos first claimed were accessed.
The stolen database contains highly sensitive personal information. It includes names, physical addresses, phone numbers, email addresses, customer ID numbers, and dates of birth. Even specific on-site search histories were compromised. Hackers can see if users searched for terms like “Asos petite,” “reclaimed vintage,” or “glamorous wide fit.”
How the Attack Happened
How did the attackers get in? Asos explained that hackers managed to trick an employee. By pretending to be a trusted contact, the scammers successfully stole login credentials, which they then used to download customer databases from an unnamed service.
The breach first became public on Tuesday. Users worldwide were shocked when a rogue push notification popped up on the official Asos app. Shortly after, the company notified shareholders via the London Stock Exchange that basic contact details might have been accessed. The latest revelations show the intrusion went far deeper.
The hackers, operating under the name Xuanyewen, told the BBC they targeted a platform called Simon AI, which runs natively on Snowflake’s data storage network. While Snowflake has stated its own systems were not breached, the hackers insist they exploited this connection to pull the data.

Concerns Over Phishing and Future Scams
For customers like Harriet, who has used the site since 2019, the news is deeply unsettling. She pointed out that stolen data like this often fuels future, more targeted scams.
“What I find particularly worrying is the possibility that stolen data can be used as a tool for future attacks,” she said, noting that the impact could last long after the initial breach.
Security experts agree. Armed with these specific details, criminals can easily build highly convincing phishing campaigns, pretending to be from companies the victim actually trusts.
Asos has not yet confirmed the exact number of affected users. However, they stressed that passwords and banking details remain completely safe. The website and app are still fully operational.
In an email to customers, Asos urged people to stay alert. “Please remain cautious of unexpected messages or calls claiming to be from Asos,” the company warned, reminding users they will never ask for passwords or payment details out of the blue.
Trevor Dearing, a security director at cybersecurity firm Illumio, warned consumers to look out for high-pressure tactics. “Expect scammers to mention the attack, use your personal details to seem genuine, and create urgency,” Dearing said.