Hackers breach ASOS systems and access customer search data
Global fashion retailer ASOS confirmed hackers compromised an employee account, accessing personal details and search histories after sending unauthorized push notifications.
FTMQ Security, written by our newsroom0 views

Hackers accessed customer information at online retailer ASOS after tricking an employee into revealing login credentials. Malwarebytes Labs, The Record, and Claims Journal all reported that the unauthorized access allowed attackers to send a rogue push notification directly through the ASOS mobile application. Customers received the push notification earlier in the week informing them that the company had suffered a cyberattack. [1][2][6]
ASOS initially stated that attackers only obtained basic personal information. However, reporting by the BBC and Malwarebytes Labs revealed that the compromised data includes customer shopping searches alongside names and contact details. ASOS confirmed that payment card information and account passwords were not accessed during the incident. [1][4][5]
According to BankInfoSecurity, the hackers claimed they breached a Snowflake-connected system called Simon AI to execute the intrusion. The incident highlights ongoing risks regarding social engineering attacks against corporate employees to obtain administrative or service credentials. [2][3][6]
Malwarebytes Labs warned that the exposure of specific shopping search histories alongside personal contact details enables attackers to craft highly targeted phishing messages. Security teams advise ASOS customers to remain vigilant against suspicious emails or communications impersonating the retailer. [1][5]
In short
- Hackers tricked an ASOS employee to gain access to corporate credentials.
- Attackers sent an unauthorized push notification to users through the ASOS mobile app.
- Stolen information includes customer contact details and shopping search queries.
- ASOS confirmed that payment card data and account passwords were not accessed.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]ASOS breach update: Hackers stole customer details and shopping searchesMalwarebytes Labs, 1d ago (the report this story comes from)
- [2]ASOS: Hackers tricked way into employee account before sending rogue push notificationThe Record from Recorded Future News, 2d ago
- [3]Asos Hackers Claim Breach of Snowflake-Connected Simon AIBankInfoSecurity, 20h ago
- [4]Asos Hackers Took More Details Than First RevealedBBC, 2d ago
- [5]ASOS breach update: Hackers stole customer details and shopping searchesMalwarebytes, 1d ago
- [6]Hackers Tricked Asos Employee to Steal Work Account LoginClaims Journal, 1d ago
Background
- [7]AFRINIC on Wikipedia
Our newsroom writes these reports with the help of software, from the 7 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- ASOS confirms data breach following social engineering attack on employee credentialsData Breaches, 2d ago
- ClickFix Social Engineering Attacks Evolve to Hide Payloads in Browser CachesTop Stories, 4d ago
- Hackers abuse Google Ads and Bing redirects in Claude ClickFix attacksTop Stories, 1d ago
More in Cybercrime and Scams
- Attackers hijack three country code domains to obtain unauthorized Google certificates1h ago
- Anthropic launches free artificial intelligence security scanning service for open source maintainers1h ago
- High severity NVIDIA DCGM Exporter vulnerability threatens internet exposed GPU servers1d ago
- CISA adds actively exploited Citrix NetScaler zero day to KEV catalog5d ago
- Google freezes open source bug bounty program over invalid AI reports5d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.