After a 48-hour investigation of the data breach that hit ASOS, cybersecurity experts have come to conclude that hackers obtained log-in credentials by gaining access to an employee account.

The threat actors successfully managed to impersonate a trusted contact. They used the employee account details to access ASOS’s “information on third-party platforms,” according to the BBC.

ASOS is a well-renowned online British fashion retailer that had 23 million active buyers in 2023, the majority of whom were based in the UK, as per Business of Apps. BBC reported that ASOS has a global footprint catering to about 17 million customers each year across 150 markets.

em360tech image

This data breach has now raised significant concerns over the security of customer information the company holds.

ASOS Shares Drop By 10%

On Tuesday, Reuters noted that ASOS shares dropped by 10 per cent; however, earlier today the retailer’s shares were up by 3 per cent, “pairing losses for the week to 8 per cent.”

ASOS has not asked their customers to take any action at this moment. However, cybersecurity experts are warning people to take extra precautions by changing passwords in case of any future potential attacks.

Although passwords were reportedly not stolen during the data breach, Trevor Dearing, Senior Director of Critical Infrastructure at Illumio, says to “be highly suspicious of any unsolicited text or email asking you to change or share yours,” as reported by the BBC.

The BBC also warned that customers could face an increased risk of phishing emails and scam calls following the breach.

Scammers may refer to the ASOS attack and use customers' personal information to make their communications look genuine. They may also create a sense of urgency, such as by threatening to lock an account unless immediate action is taken.

ASOS has reassured customers that their website and application remain safe to use, stating, “We know our customers trust us with their information”.

They further stated that the company takes their “responsibility seriously” and has already introduced additional measures to advance their security protocols.