Asos hackers gained access to millions of customers’ recent search histories as well as names, addresses and phone numbers, the online fashion retailer has revealed.
Terms typed in by customers such as “glamorous wide fit” and “Asos petite” were in the data accessed in the cyber-attack, which emerged on Tuesday after app users received a notification titled “Asos hacked” with a link to the Telegram messaging service.
After carrying out a “detailed, 48-hour investigation” into the incident, Asos confirmed on Thursday that basic personal information had been accessed by an unidentified third party. This included delivery and email addresses, names and phone numbers.
Experts said the extra information could help attackers devise “highly convincing” phishing scams targeted at customers.
Hackers gained access to a database of one of Asos’s third-party service providers by impersonating a “trusted contact” to gain access to one of its employee’s accounts, the retailer said.
Asos said they had also gained access to “certain non-personal account related information”, which are understood to include shoppers’ recent search history on the app, as first reported by the BBC which was contacted by the hackers.
Payment card details and passwords had not been accessed, the retailer added. It said in a message to customers on Thursday: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos.
“The affected platforms were immediately locked down, ensuring that no further information could be accessed, and a full investigation was launched with the support of both internal and external cyber experts. We are also working with the relevant law enforcement and regulatory authorities.”
Asos said its website and app continued to be safe to use, that customers did not need to take action and that it had “already taken additional steps to further strengthen security controls”.
However, the company warned: “Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
Charles Allen, an analyst at Bloomberg Intelligence, said the hack might “temporarily cap the pace” of Asos’s attempt to revive sales and profits, after the Covid pandemic led to a period of boom followed by a sharp drop in trade. “The loss of customer trust could weigh on efforts to rebuild its client base,” he said.
Asos pledged to contact customers directly once its investigation was complete and “where we believe additional information, support or action may be required”.
The Telegram channel operated by the purported hackers, who have named themselves the Xuanye Group, to which users were directed on Tuesday carried a message assuring Asos customers that “payment information is not affected”.
Experts said they had not heard of the group before and that the push notification could have been an attempt to gain wider attention.
skip past newsletter promotionFree newsletter |Every weekday
Sign up to Business Today
Get set for the working day – we’ll point you to all the business news and analysis you need every morning

after newsletter promotion
Simon Phillips, the chief technology officer at the cybersecurity firm CybaVerse, said the admission that a wider array of customer information was accessed than previously thought could lead to more persuasive phishing attempts.
“Given the information contained search data, and that Asos regularly sends customers reminder emails about the items they search for on the site, attackers could have used this data to send highly convincing scams which are disguised as the emails they typically receive from Asos,” he said.
Lisa Barber, the tech editor for the consumer watchdog Which?, said: “Shoppers should be especially wary of unexpected phone calls, texts, messages and emails they receive in the coming weeks and months.”
She said that if shoppers were unsure who they were speaking to, they should end the conversation and contact the company directly.
It is possible to dial 159 to speak to your bank’s fraud team, or use the number on the back of your card. If you have been called by a possible fraudster, wait at least 15 minutes before calling or use a different phone to ensure the scammer is no longer connected to the call, she said.
The hack comes after a number of British retailers, including Marks & Spencer, the Co-op and Harrods, suffered damaging cyber incidents last year. M&S and the Co-op experienced stock shortages, and the former was forced to shut down its website for several weeks while it ensured its systems were clean.