Malwarebytes reports that stolen ASOS data included contact details and website searches. Customers should check account questions through the official app or website, not through unexpected message links.
In 60 seconds
- ASOS users should watch for messages about refunds, deliveries, account problems, or the reported breach.
- The supplied report identifies no public checker for affected customers.
- Open the official ASOS app or type its website address yourself to check your account.
- Do not follow unexpected links or share passwords, security codes, or payment details.
Who should care and what to do today
This report concerns people with ASOS accounts and anyone who receives a message claiming to involve an ASOS account, delivery, refund, or the reported breach. The report does not say that every ASOS customer’s information was taken.
The supplied report identifies no public exposure checker. If you use ASOS, open the official app or type the website address yourself to review your account. If something looks wrong, contact ASOS through a route you find independently.
General guidance: do not reply to an unexpected message with a password, security code, or payment information. Do not follow the Telegram link mentioned by the attackers or engage with them.
What information was reportedly taken
Malwarebytes reports that attackers accessed customer information after tricking an employee into handing over login credentials. The report says the information included names, home addresses, phone numbers, email addresses, customer numbers, dates of birth, when customers started using ASOS, and searches made on the ASOS website.
The BBC reportedly received a sample from the attackers. It included searches such as “reclaimed vintage,” “glamorous wide fit,” and “Asos petite.” These searches can reveal shopping interests or a customer’s connection to ASOS.
Malwarebytes reports that ASOS said payment card information and customer passwords were not accessed. It also reports that ASOS said its website and app remain safe to use, locked down the affected third-party platforms, and began an investigation.
Why a real detail can appear in a fake message
Phishing is a fake message designed to trick someone into clicking a link or giving away information. Stolen names, contact details, and shopping searches could help a scammer make a message about ASOS sound personal.
A message might mention a delivery, refund, account problem, or shopping interest. It could then ask you to sign in, confirm payment details, or open a file. A correct detail does not prove that the message came from ASOS.
General guidance: check through a separate route. Open the ASOS app or website directly instead of using the message’s link. If a caller claims there is a problem, end the call and find the company’s contact route yourself.
What the report says about the systems involved
The attackers’ first notification named Snowflake, a data storage and analysis platform. They later told the BBC that they accessed the information through Simon AI, a platform ASOS uses for customer personalization.
Snowflake said it found no compromise of its platform. The supplied report says the available information does not show a security flaw in Snowflake or Simon AI. Using stolen login credentials to reach a connected service does not by itself show that the service itself was breached.
Malwarebytes reports that the attackers threatened to release the data and reportedly demanded a ransom. ASOS said its investigation would continue and that it would contact customers directly when it believed more information, support, or action was needed.
Does this affect me?
- Who may be affected
- The alert concerns ASOS customers and people who receive messages claiming to involve an ASOS account, delivery, refund, or the reported breach. The report does not say that every customer was affected.
- How to check
- Consider whether you use ASOS, then review messages that mention specific ASOS activity. The supplied report identifies no public exposure checker; ASOS says it will contact customers when further action is needed.
- What to do
- Open the official ASOS app or type the website address yourself to check your account. Contact ASOS through a route you find independently if something seems wrong.
- What to avoid
- Avoid links in unexpected messages, the attackers’ Telegram link, and requests for passwords, security codes, or payment details.
Common questions
Can I trust an ASOS message that knows my name or shopping search?
Not based on that detail alone. Malwarebytes reports that names and ASOS shopping searches were among the information taken, so scammers could use them to make a message sound personal. Check through the official app or website instead.
Do I need to change my ASOS password?
The supplied report says ASOS stated that customer passwords were not accessed. It does not give a password-change instruction. If you need to review your account, use the official ASOS app or website rather than a link in an unexpected message.
Was my payment card information stolen?
Malwarebytes reports that ASOS said payment card information was not accessed. The report does not say that every customer’s information was taken. Do not provide payment details in response to an unsolicited message or call.
What should I do with a Telegram link about the breach?
Do not follow it or engage with the attackers. Use the official ASOS app or website for account questions, and treat unexpected breach-related messages as possible phishing.
Primary source
This article is based on Malwarebytes’ report, “ASOS breach update: Hackers stole customer details and shopping searches,” published October 9, 2026. The report cites statements from ASOS and reporting by the BBC and The Independent: https://www.malwarebytes.com/blog/data-breaches/2026/10/asos-breach-update-hackers-stole-customer-details-and-shopping-searches Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Oct 9, 2026 at 7:08 am EDT. Updates and corrections are noted here when material facts change.
