Leadership1 publisherNot yet confirmed elsewhere2 min readPublished
Asos widens its breach disclosure after hackers share a data sample with the BBC
Asos says hackers took detailed profiles of potentially millions of customers, after first telling investors only basic contact details may have been accessed. The revision followed the attackers' approach to the BBC, so the people holding the records set the timing of the fuller disclosure.
The Board Room · Leadership desk

What happened
- The breach came to light on Tuesday, when the attackers pushed a pop-up notification through Asos's own app to potentially millions of people.
- The stolen profiles hold names, addresses, phone numbers, emails and customer numbers, along with the searches customers made on the Asos website.
- No bank details or passwords were accessed, according to Asos.
- Asos says customers are not being asked to take any action, and that its website and app are safe to use.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure A caller who can recite a shopper's address, customer number and recent searches is harder to tell from a genuine Asos contact than a generic phishing email.
- cost Asos asks nothing of customers beyond caution, so the job of judging each call or email that claims to come from Asos falls on the people whose profiles were taken.
- precedent A first notice that names data categories before the investigation has fixed them can be overtaken within the same week by whoever holds the stolen files.
- exposure Until Asos names the service behind the employee login, companies using the same data suppliers cannot tell whether the attackers' claimed route applies to them.
The first statement was written to the attackers' timetable. Their pop-up had already gone out [11] when Asos told the London Stock Exchange that an "unauthorised third party" was responsible and that "basic personal information including name and contact details may have been accessed" [12]. Its customer email used similar wording [12].
The trade-off in that wording was speed against completeness. A skeptic would say Asos was accurate, since "may have been accessed" claims no more than the company knew that day [12]. The difficulty is the word "basic". A shopper who read it had little reason to expect a stranger to know their address, their customer number, or that they had searched the site for "glamorous wide fit" [5]. The attackers held all of that [5].
We do not know yet whether Asos had found the wider loss before the BBC told it of the attackers' approach [4]. The group sent the BBC its sample on Wednesday evening [13]. The BBC then held its article so Asos could write to customers first [14]. Asos did not respond to the BBC's questions about the scale of the breach [10].
The stolen profiles suit the same technique that got the attackers in. Asos told customers the hackers "gained access to an Asos employee account by impersonating a trusted contact to obtain log in credentials" [16]. The BBC reported that, with the profiles, scammers may be able to craft potent phishing emails or phone calls [6]. Asos told customers, "Please remain cautious of unexpected messages or calls claiming to be from Asos" [8]. It added: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call" [9].
The route to the data is disputed. Asos says the hackers used that login to an unnamed service to download the customer data [16]. Their pop-up claimed they had "compromised the Snowflake instance" [17]. The group, calling itself Xuanyewen, claimed to the BBC that it used Simon AI, a platform built natively on Snowflake [18]. Snowflake has previously said its platform had not been breached [19]. Simon AI had been contacted for comment [18].
The decision in front of Asos this quarter is how its next statement is built. The company said it has "already taken additional steps to further strengthen security controls" [2], and it is still investigating how the hack happened [15]. If the scale of the breach again reaches the public before Asos publishes it, the company's own notices will count for less with customers it has already asked to be cautious of messages claiming to be from Asos [8].
What to watch
- Whether Asos publishes a customer count or further data categories as its investigation into the employee-account compromise continues.
- A response from Simon AI, or any change in Snowflake's position, on the attackers' account of how they reached the data.
- Reports of scam calls or emails that quote Asos customer numbers or search history back to shoppers.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives65
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Asos said customers are not being asked to take any action and that its website and app are safe to use.
ReportedSupportedSource: Asos, via BBC News2 sources— create a free account to open themView cited source - [2]
"We take that responsibility seriously and have already taken additional steps to further strengthen security controls,"
ReportedSupportedSource: Asos, via BBC News2 sources— create a free account to open themView cited source - [3]
Asos told its customers that hackers are in possession of detailed profiles of potentially millions of the online store's users.
- [4]
Asos issued its update after BBC News told the retailer it had been contacted by cyber criminals who said the breach went beyond the 'basic contact details' Asos previously said might have been accessed.
- [5]
Names, addresses, phone numbers, emails and customer numbers are in the hands of cyber criminals, as are the searches customers made on the Asos website, with terms such as 'reclaimed vintage', 'glamorous wide fit' and 'Asos petite' visible in the data.
- [6]
With this information, scammers may be able to craft potent phishing attack emails or phone calls; the risk to individuals is now higher and customers are being warned about potential impersonation scams.
- [7]
Asos confirmed data profiles were taken but said no bank details or passwords were accessed.
- [8]
"Please remain cautious of unexpected messages or calls claiming to be from Asos,"
- [9]
"We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
- [10]
Asos did not respond to questions about the scale of the breach.
- [11]
On Tuesday cyber criminals used Asos's own app system to send a pop-up notification to potentially millions of people.
- [12]
Later on Tuesday Asos confirmed to shareholders via the London Stock Exchange that the pop-up was sent by an "unauthorised third party" and that "basic personal information including name and contact details may have been accessed"; it then sent customers an email with similar wording.
- [13]
On Wednesday evening the cyber criminals responsible contacted the BBC, sharing a sample of the stolen data which showed the true extent of the hack.
- [14]
The BBC held off publishing its article to allow Asos to contact its customers first.
- [15]
Asos said it is still investigating how the hack happened.
- [16]
Asos told customers hackers "gained access to an Asos employee account by impersonating a trusted contact to obtain log in credentials"; with that log in to an unnamed service, the hackers were able to download the customer data.
- [17]
In the pop-up notification sent to customers, the hackers claimed they had "compromised the Snowflake instance".
ReportedInsufficientSource: Hackers' pop-up notification, via BBC News2 sources— create a free account to open themView cited source - [18]
The cyber criminals, calling themselves Xuanyewen, claimed to the BBC they used Simon AI, a platform built natively on top of Snowflake, to gain access to the data; Simon AI has been contacted for comment.
ReportedInsufficientSource: Claim by the hackers to BBC News2 sources— create a free account to open themView cited source - [19]
Snowflake previously said its platform had not been breached.
ReportedInsufficientSource: Snowflake, via BBC News2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- bbc.co.ukAsos hackers took more personal details than first revealed, BBC finds
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Cloud data platform securityFollow
- Breach DisclosureFollow
- Data BreachesFollow
- Phishing and Social EngineeringFollow