ASOS Confirms Cyber Attack on Customer Data
Online retailer ASOS has confirmed a cyber attack involving unauthorized access to customer names, contact details, and search histories.
Quick facts
- ASOS confirmed an unidentified third party accessed customer names, email addresses, and phone numbers.
- Hackers gained access by impersonating a trusted contact at a third-party service provider.
- The breach included search history terms, such as product preferences, stored in the database.
Why it matters
Data breaches involving third-party vendors are a recurring challenge for major e-commerce platforms. The inclusion of search history in this breach is particularly concerning for users, as it provides attackers with specific details to craft personalized and deceptive phishing messages. The long-term impact on consumer trust remains to be seen as regulatory investigations proceed.
Online fashion retailer ASOS has confirmed that an unidentified third party gained unauthorized access to a database containing customer personal information. The breach, which was revealed following a 48-hour investigation, involves names, email addresses, phone numbers, and recent search histories.
How did the breach happen?
According to ASOS, the incident originated at a third-party service provider. Attackers gained access to the system by impersonating a trusted contact to compromise an employee's account. This allowed the unauthorized party to view information stored within that specific database.
What data was accessed?
The company confirmed that the accessed information includes personal identifiers and customer search behavior. Specifically, terms typed into the site by users—such as product descriptions like “glamorous wide fit” or “Asos petite”—were included in the data exposed during the incident.
Why this is trending in Sweden
The search interest in Sweden reflects the global reach of the ASOS platform and concern among international customers regarding data privacy. While the sources do not specify a unique impact on the Swedish market, the incident has triggered widespread attention among users who rely on the retailer's app and website.
What is confirmed and what is not
ASOS has stated that their website and app remain safe for continued use. The company is currently working with legal and regulatory authorities to address the situation. It is not confirmed if further data types were exposed or if specific customer accounts have been targeted for subsequent malicious activity, though security experts have warned that the stolen information could be utilized for sophisticated phishing attempts.
Frequently asked questions
What information was taken in the ASOS breach?
ASOS confirmed that hackers accessed customer names, delivery and email addresses, phone numbers, and recent search histories. The breach occurred at a third-party service provider rather than directly through the main ASOS internal systems.
Is the ASOS website and app safe to use?
According to the retailer, the ASOS website and app are safe to use. The company stated it is working with relevant legal and regulatory authorities to manage the aftermath of the security incident.
How did the hackers get access to the data?
The attackers gained access by impersonating a trusted contact to compromise an employee account at one of ASOS's third-party service providers. This allowed them to breach the database containing the customer information.
Why should I be concerned about my search history?
Security experts warn that the stolen search history, combined with personal contact details, could be used by attackers to create highly convincing phishing scams that appear tailored to your specific shopping interests.
How was the breach discovered?
The incident came to light after users reported receiving a notification titled “Asos hacked,” which contained a link to the Telegram messaging service. ASOS subsequently conducted a 48-hour investigation to confirm the extent of the unauthorized access.
What should I do if I am an ASOS customer?
While ASOS has not provided specific instructions for individual users, experts generally advise being vigilant against unexpected emails or messages that claim to be from the retailer, especially those requesting personal information or account credentials.
In this story
Sources
Trend snapshot
- Topic
- Business
- Trending in
- Sweden
- Search interest
- 1000+ recent searches
- Status
- Verified: 3 independent outlets
- Last updated
- Oct 9, 2026 at 7:30 AM
Peak: 7K+ searches, 2 days ago. Strongest in: Sweden (1K+).
Last checked Oct 9, 2026 at 7:30 AM. Trends move fast, so details may change. How we work · How we verify
Comments