Asos says hacker accessed customers’ search histories along with names and contact details

Hackers gained access to a database of one of Asos’s third-party service providers by impersonating a 'trusted contact' to gain access to one of its employee’s accounts, the retailer said.

Hackers gained access to a database of one of Asos’s third-party service providers by impersonating a 'trusted contact' to gain access to one of its employee’s accounts, the retailer said.

Asos hackers gained access to millions of customers’ recent search histories as well as names, addresses and phone numbers, the online fashion retailer has revealed.

Terms typed in by customers such as “glamorous wide fit” and “Asos petite” were in the data accessed in the cyber attack, which emerged on Tuesday after app users received a notification titled “Asos hacked” with a link to the Telegram messaging service.

After carrying out a “detailed, 48-hour investigation” into the incident, Asos confirmed on Thursday basic personal information had been accessed by an unidentified third party. This included customers’ delivery and email addresses, names and phone numbers.

Hackers gained access to a database of one of Asos’s third-party service providers by impersonating a “trusted contact” to gain access to one of its employee’s accounts, the retailer said.

Asos said it had also gained access to “certain non-personal account related information”, which are understood to include shoppers’ recent search history on the app.

Payment card details or passwords had not been accessed, the retailer added. It said in a message to customers on Thursday: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos.

“The affected platforms were immediately locked down, ensuring no further information could be accessed, and a full investigation was launched with the support of both internal and external cyber experts. We are also working with the relevant law enforcement and regulatory authorities.” 

It said the Asos website and app continued to be safe to use, that customers did not need to take action and it had “already taken additional steps to further strengthen security controls”.

However, the company warned: “Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.” 

The Guardian

x

More in this section

Lunchtime News

Newsletter

Get a lunch briefing straight to your inbox at noon daily. Also be the first to know with our occasional Breaking News emails.

Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited