ASOS Faces Data Breach: Customer Details Exposed
UK fashion retailer ASOS has recently alerted its customers regarding a significant data breach that occurred on October 6. This incident has raised concerns about the security of personal and account data, leading to heightened scrutiny from customers and cybersecurity experts alike.
In a customer email dated October 8 and disclosed by Infosecurity, ASOS reassured clients that their payment information remained secure and that ongoing operations were not disrupted as a result of the breach. The company has sought to maintain transparency about the incident while emphasizing that it is taking necessary steps to mitigate any potential consequences.
Upon further investigation, ASOS discovered that the breach stemmed from an employee account that had been compromised. According to ASOS, the attacker successfully impersonated a trusted associate, thereby tricking the employee into revealing their login credentials. These compromised credentials were subsequently utilized to access data on various third-party platforms utilized by ASOS.
Third-Party Platform Access: A Key Factor
In a formal communication to the London Stock Exchange released on the same day as the breach, ASOS acknowledged that the investigation was focusing on the third-party platforms used to engage with customers. Access to these platforms allowed the threat actor to send out a push notification that appeared to originate from ASOS itself.
The notification claimed that the attacker had compromised a Snowflake instance, a cloud-based data platform that many organizations use for storing, managing, and analyzing extensive volumes of data. A spokesperson for Snowflake confirmed their immediate initiation of an investigation upon discovering the falsified notification and stated that, as of now, there was no evidence of a compromise within their platform.
However, Pieter Arntz, a senior malware intelligence researcher at Malwarebytes, indicated that Simon AI—a marketing tool employed by ASOS—might be indirectly linked to this breach, given that it is built on Snowflake Cortex AI. The platform has been publicly acknowledged for its collaboration with both ASOS and other notable American clothing brands.
On October 8, BBC reported a conversation held by cybersecurity journalist Joe Tidy with the alleged threat actor, who claimed that a Simon AI instance was compromised to siphon off customer data. The American software firm Monetate, which acquired Simon AI in July, has been approached for further comment on the matter.
Detailed Data Compromised
While the threat actor initially stated in a Telegram channel linked to the push notification that only "customer information" was involved and that it would remain safe on their server for a significant period, allegations have arisen suggesting that the data may contain more than just basic contact details. The BBC claimed to have received a sample of the stolen data, which includes a much broader spectrum of information. Customers could potentially face exposure of names, addresses, phone numbers, email addresses, customer identifiers, and even specific search queries conducted on the ASOS website. Terms like "reclaimed vintage," "glamorous wide fit," and "ASOS petite" reportedly surfaced in the stolen data.
The legitimacy of the data provided by the threat actor has yet to be confirmed, as noted by the BBC, sparking questions about the actual extent of the breach. This latest incident comes on the heels of a previous Infosecurity report indicating that the Telegram account associated with the hack may have ties to gaming item trading activities, further complicating the narrative surrounding the breach.
Cybersecurity expert Anastasia Tikhonova, who heads threat research at Group-IB, pointed out that the Telegram channel referenced in the notification was newly established on October 6. Information gleaned from their monitoring system revealed that the Telegram account behind the current iteration had operated under different names in the past, specifically associated with gaming-item trading. Those names included JohnCZ and Moon Transfers, indicating a potentially longstanding history behind the account that now goes by @xuanyegroup.
Conclusion
As ASOS strives to address the fallout from this breach, customers remain alert regarding the security of their personal data. The intersection of advanced cyber threats and inadequately secured employee credentials poses challenges not just for ASOS, but for retailers and organizations across the board. This incident serves as a stark reminder of the growing vulnerabilities that businesses must contend with in an increasingly digital world, urging a reevaluation of cybersecurity protocols and employee training programs to prevent future occurrences.

