Asos has confirmed that an unauthorized party accessed customer data after acquiring login credentials by impersonating a trusted contact. The company issued a statement following customer reports of a mobile app notification titled “Asos hacked,” which directed users to a Telegram account.
The fast fashion retailer said it conducted a thorough investigation and determined that the breach originated from an Asos employee account compromised through social engineering tactics. The attacker used the stolen credentials to access information stored on third-party platforms utilized by the company.
In response, Asos immediately secured the affected platforms to prevent further unauthorized access. The investigation revealed that some personal data, including customer names and contact details, were accessed during the breach. Additionally, the intruder obtained certain non-personal account-related information.
Asos has apologized to customers for the incident and urged them to remain vigilant against unexpected communications purporting to be from the company. Customers were advised not to engage with the fraudulent notifications or linked messages as the retailer works to address the situation and enhance security measures.
