
Cyber criminals accessed search history and contact details, raising the risk of targeted phishing scams.
Asos confirmed that hackers stole detailed user profiles containing names, addresses, phone numbers, and website search history, increasing the risk of targeted phishing and impersonation scams for potentially millions of customers.
AI-generated summary
Cyber criminals breached Asos using its own app system to send a pop-up notification to users.
Asos has told its customers that hackers are in possession of detailed profiles of potentially millions of the online store's users.
It issued the update after BBC News told the retailer it had been contacted by cyber criminals who said this week's breach went beyond the "basic contact details" Asos previously said might have been accessed.
Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.
So too are the searches customers have made on the website. Terms like "reclaimed vintage", "glamorous wide fit" and "Asos petite" are visible in the data.
With this information, scammers may be able to craft potent phishing attack emails or phone calls.
The risk to individuals is now higher and customers are being warned about potential impersonation scams.
In its email to customers, Asos confirmed data profiles were taken but said no bank details or passwords were accessed.
"Please remain cautious of unexpected messages or calls claiming to be from Asos," it said.
"We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
The company did not respond to questions about the scale of the breach.
The high profile hack made global headlines on Tuesday when cyber criminals used Asos's own app system to send a pop up notification to potentially millions of people.
Later that day the firm confirmed to shareholders via the London Stock Exchange that the pop up was sent by an "unauthorised third party" and "basic personal information including name and contact details may have been accessed."
The company then sent an email to customers with similar wording.
On Wednesday evening the cyber criminals responsible contacted the BBC sharing a sample of the stolen data which showed the true extent of the hack.
The BBC held off publishing this article to allow Asos to contact its customers first.
AI outlook — possibilities, not facts
Customers will face targeted phishing attempts using stolen data.
Likely · Within weeks

Russia is systematically targeting Ukrainian data centers and digital infrastructure to disrupt information flows and services, though experts say a total internet blackout is unlikely due to sector decentralization.

Former PlayStation executive Shawn Layden criticized Sony's reported plan to end physical game disc production by 2028, warning it harms the brand and shifts ownership to mere access.
Union minister Ashwini Vaishnaw announced India will release an AI regulation consultation paper next month focusing on safety, deepfakes, and a techno-legal approach.

Ukrainian drones hit an important Yandex data center in Sasovo, Russia, for the first time, causing a fire. Operations were stopped and, according to media reports, there were no injuries.
Insurance fraudsters use artificial intelligence to produce photos of non-existent damage to vehicles and receive compensation. FraudFlow CEO Güneş İnal announced that they detected artificial damage worth 6.5 million TL in 39 suspicious files.

The first RTX Spark supported laptops containing NVIDIA Blackwell RTX GPU and Grace CPU units are available for pre-order in Türkiye. Prices of Asus, Lenovo and MSI models vary between 210 thousand TL and 424 thousand TL.