ASOS Breach: Millions' Search Histories Exposed | Analysis

ASOS data breach exposed millions of customers' names, addresses, phone numbers and search histories on 8 October 2026. Learn the protection steps.

ASOS Breach: Millions' Search Histories Exposed | Analysis
Share
Share this article Choose a network or an app on your device.
Email

Edition: EN

Online fashion retailer ASOS has confirmed that hackers accessed personal data belonging to millions of customers, including names, addresses, phone numbers and recent search histories. The 8 October 2026 disclosure dramatically widened the scope of the ASOS data breach beyond the “basic contact details” the company first described, after shoppers received an “ASOS hacked” push notification linking to a Telegram channel.

What is the ASOS data breach?

The ASOS data breach began on 6 October 2026, when thousands of app users across the UK and other markets received an unauthorised push notification through ASOS’s own verified app channel. The message, addressed to the company’s data protection officer, claimed attackers had “fully compromised the Snowflake instance” and threatened to leak data unless ASOS engaged with them, according to BBC reporting. A group calling itself the Xuanye Group (or Xuanyewen) claimed responsibility.

By 8 October, ASOS confirmed the attacker had impersonated a “trusted contact” to phish credentials from a single employee at a third-party service provider. Those credentials were then used to access legitimate customer-communication platforms, exposing detailed customer profiles. This incident echoes wider patterns in the UK retail cyber attacks that have hit Marks & Spencer, the Co-op and Harrods in recent years.

What data was stolen from ASOS customers?

ASOS initially said only “basic personal information” such as names and contact details may have been accessed. However, the BBC reported that cyber criminals claimed the breach went well beyond that. The exposed records now include:

  • Full names
  • Home and delivery addresses
  • Email addresses and phone numbers
  • Customer numbers
  • Dates of birth
  • Account start dates
  • Recent on-site search terms, such as “reclaimed vintage” and “Asos petite”

ASOS says payment card details and passwords were not taken, and its website and app continue to operate normally. Snowflake, the cloud data platform named in the hackers’ message, said it found no compromise of its own systems; the attack instead targeted Snowflake-based customer data platforms such as the personalisation tool Simon AI.

Why stolen search histories are dangerous

Security experts warn that search histories are far more sensitive than basic contact details. Search terms reveal shoppers’ sizes, interests, life events and shopping habits, which can make phishing attempts far more convincing. “The stolen search data could fuel highly convincing phishing scams mimicking ASOS reminder emails,” one expert told The Guardian. Attackers threatened to leak the data and demanded a ransom within two weeks, a textbook ransomware and extortion tactic aimed at pressuring the retailer.

How ASOS and regulators are responding

ASOS locked down the affected notification platforms, ran a 48-hour investigation and said it is working with law enforcement and regulators. The UK’s National Cyber Security Centre (NCSC) has offered assistance. The company’s shares fell around a tenth after the initial notification, despite ASOS noting it holds cybersecurity insurance. The incident raises fresh questions about data protection regulation enforcement and whether the Information Commissioner’s Office (ICO) will open a formal investigation into how employee credentials were phished.

How to protect yourself after the ASOS breach

If you use ASOS, security experts recommend taking these steps immediately:

  1. Do not click the Telegram link in the “ASOS hacked” notification.
  2. Change your ASOS password and any identical passwords used on other sites.
  3. Enable two-step verification on email and banking accounts.
  4. Monitor bank and card statements for unusual transactions.
  5. Be suspicious of follow-up emails, texts or calls claiming to be from ASOS.

Frequently asked questions

Was my ASOS password stolen?

ASOS says passwords and payment card details were not accessed. However, you should still change your password as a precaution.

What should I do if I received the “ASOS hacked” notification?

Do not click the link. Update your password, enable two-step verification and watch for phishing messages.

How many ASOS customers were affected?

ASOS has not published an exact figure, but described the breach as affecting “millions” of customers.

Is the ASOS website safe to use now?

ASOS says its website and app remain safe and operational, though experts suggest remaining cautious about unsolicited messages.

Conclusion

The widening ASOS data breach shows how quickly a single phished employee account can expose millions of customer profiles, including intimate shopping search histories. As the retailer continues its investigation, the episode serves as a stark reminder of the growing consumer data privacy risks in online retail.

Closely related