Asos has informed its customers that cyber criminals have obtained comprehensive personal profiles affecting potentially millions of users of the online retailer, significantly expanding the initial assessment of the security incident.
The fashion retailer issued this clarification following contact from a national broadcaster who reported being approached by the hackers themselves. The criminals indicated that the breach extended well beyond the "basic contact details" that Asos had initially suggested might have been compromised.
The stolen information now confirmed to be in criminal hands includes names, addresses, telephone numbers, email addresses and customer account numbers. Additionally, the data encompasses search histories showing the specific terms customers entered on the platform, such as "reclaimed vintage," "glamorous wide fit" and "Asos petite."
Armed with this combination of personal and behavioural information, fraudsters now possess the tools to construct convincing phishing campaigns and impersonation schemes targeting affected individuals. The expanded scope of exposed data significantly elevates the risk profile for customers.
In a message sent to its user base, Asos acknowledged that customer data profiles had been extracted during the breach but stated that financial information and login credentials remained secure. The company advised customers to exercise heightened vigilance:
"Please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
Asos declined to provide specifics regarding the total number of affected accounts or the complete scope of the incident.
How did the breach unfold?
The incident gained international attention on Tuesday when cyber criminals exploited Asos's own application infrastructure to distribute a pop-up notification to potentially millions of users. According to regulatory filings, the notification was sent at approximately 10am on 6 October and involved third-party communication platforms that Asos uses to reach customers.
Later that same day, the company notified shareholders through the London Stock Exchange that an "unauthorised third party" had sent the pop-up and that "basic personal information including name and contact details may have been accessed." Asos subsequently sent a similar statement to its customer base.
On Wednesday evening, the attackers contacted a national broadcaster and provided samples of the stolen data, revealing the true extent of what had been compromised. The message linked to a Telegram channel identified as "Xuanye Wen Gateway." According to reporting, a group calling itself Xuanye gave Asos two weeks to make contact and indicated it was seeking a ransom in exchange for deleting the customer information.

What is the current operational status?
Despite the severity of the breach, Asos confirmed that its website and mobile application remained fully operational with no disruption to business operations. The retailer has continued to process orders and serve customers throughout the incident.
What regulatory steps are being taken?
A national broadcaster reported that Asos had not yet notified the UK's Information Commissioner's Office about the breach at the time of the initial disclosure. The Information Commissioner's Office is the UK's independent authority responsible for data protection and privacy matters, and organisations are typically required to report significant breaches within a specified timeframe.
What happens next?
The investigation into the breach remains ongoing. Asos has not publicly disclosed a timeline for when it expects to complete its forensic analysis or provide customers with additional details about the incident. The company has indicated it will issue further updates as more information becomes available.
Key Facts:
- Stolen data includes names, addresses, phone numbers, emails, customer numbers and search histories
- The breach was executed through Asos's own app notification system on 6 October
- Attackers provided samples to media outlets and demanded contact within two weeks
- No financial information or passwords were compromised according to Asos
- The retailer's website and app continue to operate normally




