ASOS has disclosed that the data breach affecting its systems involved attackers gaining access after tricking an employee into handing over login credentials. While the retailer originally said payment card details and customer passwords were not accessed, BBC reporting cited by Malwarebytes indicates a broader set of data was exfiltrated.
The stolen information was used to access third‑party platforms that ASOS relies on, which the company has now locked down while it conducts an investigation with internal and external specialists and strengthens its security controls.
What was stolen, and why it matters, is now clearer. In addition to basic contact details, the incident exposed customer numbers and dates of birth, phone numbers and email addresses, and, notably, shopping‑related data such as product searches conducted on the ASOS site. The attackers’ notification originally named Snowflake as the data storage/analytics platform involved, with Simon AI (a platform built on Snowflake used for customer personalization) later cited as the route to the data.
Snowflake has said it found no compromise of its platform, and the available reporting does not establish a Snowflake or Simon AI vulnerability. ASOS has indicated it will contact affected customers directly as the investigation progresses, and it has warned that the stolen details could enable convincingly targeted phishing.
The guidance emphasises remaining wary of breach‑related messages and contacting ASOS only via official channels. The case highlights risks from credential compromise and the potential for attackers to tailor social‑engineering attempts using personal shopping data.