Skip to content

Leadership1 publisherNot yet confirmed elsewhere2 min readPublished

Asos widens its breach disclosure after hackers share a data sample with the BBC

Asos says hackers took detailed profiles of potentially millions of customers, after first telling investors only basic contact details may have been accessed. The revision followed the attackers' approach to the BBC, so the people holding the records set the timing of the fuller disclosure.

The Board Room · Leadership desk

How we use AISend a correction

Illustration accompanying Asos widens its breach disclosure after hackers share a data sample with the BBC
Generated illustration

What happened

  • The breach came to light on Tuesday, when the attackers pushed a pop-up notification through Asos's own app to potentially millions of people.
  • The stolen profiles hold names, addresses, phone numbers, emails and customer numbers, along with the searches customers made on the Asos website.
  • No bank details or passwords were accessed, according to Asos.
  • Asos says customers are not being asked to take any action, and that its website and app are safe to use.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure A caller who can recite a shopper's address, customer number and recent searches is harder to tell from a genuine Asos contact than a generic phishing email.
  • cost Asos asks nothing of customers beyond caution, so the job of judging each call or email that claims to come from Asos falls on the people whose profiles were taken.
  • precedent A first notice that names data categories before the investigation has fixed them can be overtaken within the same week by whoever holds the stolen files.
  • exposure Until Asos names the service behind the employee login, companies using the same data suppliers cannot tell whether the attackers' claimed route applies to them.

The first statement was written to the attackers' timetable. Their pop-up had already gone out [11] when Asos told the London Stock Exchange that an "unauthorised third party" was responsible and that "basic personal information including name and contact details may have been accessed" [12]. Its customer email used similar wording [12].

The trade-off in that wording was speed against completeness. A skeptic would say Asos was accurate, since "may have been accessed" claims no more than the company knew that day [12]. The difficulty is the word "basic". A shopper who read it had little reason to expect a stranger to know their address, their customer number, or that they had searched the site for "glamorous wide fit" [5]. The attackers held all of that [5].

We do not know yet whether Asos had found the wider loss before the BBC told it of the attackers' approach [4]. The group sent the BBC its sample on Wednesday evening [13]. The BBC then held its article so Asos could write to customers first [14]. Asos did not respond to the BBC's questions about the scale of the breach [10].

The stolen profiles suit the same technique that got the attackers in. Asos told customers the hackers "gained access to an Asos employee account by impersonating a trusted contact to obtain log in credentials" [16]. The BBC reported that, with the profiles, scammers may be able to craft potent phishing emails or phone calls [6]. Asos told customers, "Please remain cautious of unexpected messages or calls claiming to be from Asos" [8]. It added: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call" [9].

The route to the data is disputed. Asos says the hackers used that login to an unnamed service to download the customer data [16]. Their pop-up claimed they had "compromised the Snowflake instance" [17]. The group, calling itself Xuanyewen, claimed to the BBC that it used Simon AI, a platform built natively on Snowflake [18]. Snowflake has previously said its platform had not been breached [19]. Simon AI had been contacted for comment [18].

The decision in front of Asos this quarter is how its next statement is built. The company said it has "already taken additional steps to further strengthen security controls" [2], and it is still investigating how the hack happened [15]. If the scale of the breach again reaches the public before Asos publishes it, the company's own notices will count for less with customers it has already asked to be cautious of messages claiming to be from Asos [8].

What to watch

  • Whether Asos publishes a customer count or further data categories as its investigation into the employee-account compromise continues.
  • A response from Simon AI, or any change in Snowflake's position, on the attackers' account of how they reached the data.
  • Reports of scam calls or emails that quote Asos customer numbers or search history back to shoppers.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption
Insufficient
Hype gap+5
Incentives65
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Asos said customers are not being asked to take any action and that its website and app are safe to use.

    ReportedSupportedSource: Asos, via BBC News2 sources— create a free account to open themView cited source
  2. [2]

    "We take that responsibility seriously and have already taken additional steps to further strengthen security controls,"

    ReportedSupportedSource: Asos, via BBC News2 sources— create a free account to open themView cited source
  3. [3]

    Asos told its customers that hackers are in possession of detailed profiles of potentially millions of the online store's users.

    ReportedSupportedSource: BBC NewsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bbc.co.uk

    1 article · October 8, 2026

    Asos hackers took more personal details than first revealed, BBC finds

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories