ASOS has confirmed that customer information was accessed through third-party platforms after an attacker obtained an employee’s login credentials.
What happened
In an update sent to customers on 8 October, the online fashion retailer said the unauthorised party impersonated a trusted contact to gain access to the employee account.
Why it matters
According to its investigation, information accessed included names and contact details, as well as “certain non-personal account-related information”. ASOS said customers’ payment-card information and account passwords were not among the data accessed, and its website and app had remained safe to use throughout.
The BBC reported that hackers had obtained extensive profiles that could relate to millions of customers. A sample supplied to the broadcaster by people claiming responsibility contained names, addresses, phone numbers, email addresses, customer numbers and searches made on the retailer’s website.
The broadcaster said ASOS issued its update after being contacted about the findings. The information could help scammers make phishing emails or calls appear more convincing.
This news brief is based on reporting published by TheIndustry.fashion on 2026-10-08. The original report is linked below.
TheIndustry.fashion
https://www.theindustry.fashion/asos-provides-update-on-cyber-attack-as-investigation-continues/This independent news brief is based on the public source identified above. It is an original summary or translation, not a reproduction of the source article. Rights in source text, research, trademarks and images remain with their respective owners; images are used under the licence or permission identified in the credit. Rights holders may contact rights@goodproductasia.com with evidence of ownership. Verified concerns will be corrected, replaced or removed promptly. This report is not investment, legal, medical or purchasing advice.








