Asos has informed its customers that hackers have obtained detailed profiles potentially involving millions of users following a recent data breach. The company’s update came after BBC News disclosed that cybercriminals directly contacted the outlet, revealing the breach exposed more information than previously acknowledged.

The stolen data includes names, addresses, phone numbers, emails, customer numbers, and even customers’ search histories on the site. This level of detail increases the likelihood of sophisticated phishing attacks through email or phone calls.

Scope and Details of the Breach

Earlier reports from Asos indicated only “basic contact details” might have been compromised, but the hackers who contacted the BBC shared a sample of stolen data demonstrating a wider reach. The data included search terms customers used, such as “reclaimed vintage,” “glamorous wide fit,” and “Asos petite.”

Asos confirmed in its communication that while customer profiles were taken, bank details and passwords were not accessed. The company urged caution against unexpected messages or calls claiming to be from Asos, warning customers it will never ask for passwords, security codes, or payment details via unsolicited contact.

How the Hack Occurred

Investigation into the breach is ongoing. Asos said hackers gained access to an employee account by impersonating a trusted contact to obtain login credentials. Using these credentials, the attackers accessed a service that allowed them to download the customer data.

The hackers claimed they compromised an instance of Snowflake, a popular data storage and analysis platform, via a third-party native platform called Simon AI. Snowflake previously stated its platform had not been breached. Simon AI has been contacted for comment on the incident.

Response and Security Measures

Despite the breach, Asos assured customers that its website and app remain secure to use. The company emphasized its commitment to security and said it has implemented further controls to strengthen data protection.

Cybersecurity experts advise customers to change passwords as a precaution and to remain alert for any suspicious activity, especially impersonation scams that could arise from the stolen data.