According to Malwarebytes Labs, attackers stole ASOS customer information after tricking an employee into giving up login credentials. ASOS says customer passwords and payment card information were not accessed, but the stolen data reportedly includes shopping-related searches, which could make fake ASOS messages harder to spot.
What happened
ASOS customers first learned something was wrong when attackers sent a push notification through the ASOS app claiming the company had been hacked, according to Malwarebytes Labs. ASOS later confirmed that attackers used stolen employee login details to access customer information on third-party platforms used by the retailer.
Malwarebytes Labs, citing BBC reporting, says the stolen information included more than basic contact details. The BBC received a sample from the attackers and reported that some shopping search terms were included. Malwarebytes Labs said this makes the incident more sensitive than a simple contact-list leak because shopping searches can reveal interests and help scammers personalize messages.
The attackers named Snowflake in their notification, but Malwarebytes Labs says the available reporting does not show that Snowflake or Simon AI had a vulnerability. The attackers reportedly said they accessed data through Simon AI, a customer personalization platform used by ASOS and built on Snowflake. Snowflake said it found no compromise of its platform.
ASOS said it locked down the affected platforms, started an investigation with internal and external specialists, and strengthened its security controls. The company also said its website and app remain safe to use. Affected models, software versions, or technical indicators do not apply to this retail data-breach story and were not disclosed in the source.
Who is affected
The source does not give a number of affected customers or say which countries are included. ASOS is a global retailer, so any ASOS customer who receives a notice from the company should take it seriously.
ASOS says payment card details and customer passwords were not accessed. That is important, but it does not remove the phishing risk. A scammer who knows your name, contact details, or shopping interests could write a message that looks more personal and believable.
The biggest risk for households is follow-up fraud: fake refund notices, fake account alerts, fake delivery updates, or messages that push you to click a link and sign in. A message that knows something about your shopping habits is not proof it came from ASOS.
What to do now
Open the ASOS app or go to the ASOS website directly by typing the address yourself. Do not use links in texts, emails, social posts, or app notifications that claim to be urgent account alerts.
Check your ASOS account messages and email inbox for any notice from ASOS. The source says ASOS will contact customers directly where it believes more information, support, or action is needed.
Be suspicious of messages about refunds, orders, delivery problems, password resets, or account verification. If a message asks for your password, payment card, bank login, or a one-time code, stop and go to ASOS directly instead.
If you reused your ASOS password anywhere else, change it on those other accounts too. ASOS says customer passwords were not accessed, but reused passwords are still risky if another breach exposes them later.
Watch bank and card statements for unfamiliar charges. ASOS says payment card information was not accessed, but monitoring your accounts is still a sensible step after any retail breach.
Tell family members not to trust a message just because it includes a real name, phone number, address, or shopping detail. For more household scam habits, see CyberSec24’s family protection weekend guide.
Sources
- ASOS breach update: Hackers stole customer details and shopping searches — Malwarebytes Labs
Written by the CyberSec24 news desk with AI assistance, from the sources above. Spot an error? Tell us and we'll correct it.
