News

ASOS Cyber Breach: Hackers Accessed Customer Data Through Employee Account

ASOS says a cyberattack exposed some customer names and contact details after hackers compromised an employee account. Payment-card information and passwords were not accessed, according to investigations.

Written By : Poulami Saha
Reviewed By : Pranchal Srivastava

UK-based online fashion retailer ASOS confirmed that a cyberattack allowed an unauthorised party to access some customer information. The company said names and contact details were among the data accessed during the incident.

The disclosure follows a detailed investigation launched after an unauthorised notification was sent to customers through the ASOS app on October 6. The alert, which carried the message ‘ASOS hacked’, directed recipients to an external Telegram channel.

Hackers Impersonated Trusted Contact

ASOS said the attackers gained access to an employee account by impersonating a trusted contact. They obtained the employee's login credentials and then used them to access information stored on certain third-party platforms used by the retailer.

The incident highlights the growing threat from social engineering attacks. Instead of exploiting a software vulnerability directly, attackers manipulate employees or trusted users into handing over credentials.

ASOS said it immediately restricted access to the affected platforms after discovering the unauthorised activity. It also brought in internal and external cybersecurity specialists to investigate the breach.

Payment Details and Passwords Not Accessed

ASOS said its investigation found that payment-card information and account passwords were not accessed. The retailer also stressed that its website and app remained safe to use throughout the incident.

The UK National Cyber Security Centre confirmed that customer names and contact details had been accessed. ASOS said certain non-personal account-related information was also exposed.

The retailer advised customers to remain cautious about unexpected emails, messages or calls claiming to come from ASOS. It said it would never request passwords, security codes or payment information through unsolicited communications. The breach adds to growing cybersecurity concerns facing UK businesses, with retailers and other major organisations increasingly targeted by social engineering and ransomware attacks.

Also Read: Mistral CEO Says New AI Model Beats Chinese Rivals in Cybersecurity

Lexus RZ 500e Launches in UAE at AED 255,000: Check Details

GCC Scam Alert: Stolen Cards Used to Pay Government Bills

Tab Bets on Texting as AI Assistant Startup Debuts at USD 300 Million Valuation

US-Russia Nord Stream Talks: Could a Deal Revive Gas Flows?

Android’s Iconic Navigation Keys Return on Googlebook Laptops: What F1, F2, F3 Do