Wireva

Asos says customer names and contact details accessed in hack

Online fashion retailer Asos has confirmed that an unauthorised party impersonated a trusted contact to gain access to an employee account, exposing customer names and contact details. Payment information and passwords were not compromised, but the breach sent shares down about 10% and prompted an apology to affected users.

Asos has confirmed that an unauthorised party gained access to some customer personal information, including names and contact details, after impersonating a trusted contact to obtain log-in credentials for an employee account. The online fashion retailer said payment details and passwords were not compromised in the incident, which triggered a sharp fall in its share price.

Thousands of users of the Asos app received a notification on Tuesday titled «Asos hacked», directing them to the Telegram messaging service. The alert, which appeared as a phone notification, prompted confusion among customers and sent the company's shares diving by about 10%.

The retailer has since issued an apology to affected customers and confirmed that the breach involved an employee account being accessed through social engineering rather than a direct compromise of its customer-facing systems. The company said it had identified the unauthorised access and was working to secure the account.

According to Asos, the attacker posed as a trusted contact to gain log-in details, a technique that bypasses technical security measures by targeting human trust. The company has not disclosed how many customers were affected, but the notification reached thousands of app users.

The incident is the latest in a series of cyber-security challenges for major retailers, which hold vast amounts of personal and financial data. While Asos stressed that payment details and passwords remain safe, the exposure of names and contact information could leave customers vulnerable to phishing attempts and other forms of fraud.

Shares in Asos fell by around 10% following the disclosure, reflecting investor concern about the reputational and operational impact of the breach. The company's stock has been volatile in recent years amid broader pressures on online fashion retail.

Asos said it is contacting affected customers and has advised them to remain vigilant about unsolicited communications. The retailer has not commented on whether it has reported the incident to regulators or law enforcement agencies.

The breach highlights the growing threat of social engineering attacks, in which hackers manipulate employees into revealing credentials or granting access to internal systems. Such attacks are often difficult to detect because they exploit human error rather than software vulnerabilities.

For Asos customers, the immediate risk is that their names and contact details could be used in targeted phishing campaigns. The company has urged users to be cautious about any messages claiming to be from Asos and to avoid clicking on suspicious links.

Asos has not provided a timeline for when the breach was discovered or how long the unauthorised access persisted. The company said its investigation is ongoing and that it is taking steps to prevent similar incidents in the future.

The incident comes as retailers face increasing scrutiny over their data protection practices. Under UK data protection rules, companies are required to report certain breaches to the Information Commissioner's Office within 72 hours if they pose a risk to individuals' rights and freedoms.

Asos has not confirmed whether it has notified the Information Commissioner's Office. The retailer said it is prioritising transparency with its customers and will provide further updates as its investigation progresses.

The hack is a reminder that even large, well-resourced companies can fall victim to relatively simple impersonation tactics. Security experts have long warned that employee training and multi-factor authentication are critical defences against such attacks.

Asos customers who received the notification have been advised to change their passwords as a precaution, even though the company says passwords were not compromised. The retailer has also recommended enabling two-factor authentication where available.

The company's response will be closely watched by investors and regulators alike, as data breaches can lead to significant fines and long-term damage to brand trust. Asos has said it is committed to protecting customer data and will continue to review its security measures.

Same event, other desks

Story file →