GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
UK's ASOS says cyber hack accessed customers' personal data - Finance news and analysis from Global Banking & Finance Review
Finance

UK's ASOS says cyber hack accessed customers' personal data

Published by Global Banking & Finance Review

Posted on October 8, 2026

2 min read

· Last updated: October 8, 2026

Add as preferred source on Google

ASOS Reports UK Cybersecurity Hack with Customer Data Exposed, Platforms Secured

ASOS Cybersecurity Breach: Details and Response

Incident Overview

LONDON, Oct 8 (Reuters) - British online fashion retailer ASOS said on Thursday that a cybersecurity breach earlier this week had exposed some customers' personal information, including names and contact details, according to its initial investigation.

It said the hacker also had access to "certain non-personal account related information," but no payment card information or account passwords, ASOS said in an email to customers.

How the Breach Occurred

"We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," ASOS said.

"Those credentials were then used to access information on certain third-party platforms used by ASOS."

Immediate Actions Taken

It said the affected platforms were immediately locked down, ensuring that no further information could be accessed, adding that the ASOS website and app were safe to use throughout, and remain safe to use.

Ongoing Investigation and Market Impact

Collaboration with Authorities

ASOS said it is working with the relevant law enforcement and regulatory authorities.

Share Price Reaction

Shares in ASOS were up 3%, paring losses for the week to 8%.

Context: Cyberattacks in the UK

Prevalence of Social Engineering Attacks

So-called "social engineering" operations, where hackers impersonate workers to gain access to companies' computer networks, are prevalent.

Recent High-Profile Incidents

British companies and institutions have been increasingly hit by aggressive and regular cyber and ransomware attacks in recent years. The British Library, a blood testing service, the London Underground, Marks & Spencer, the Co-op and Jaguar Land Rover are some that have suffered months of disruption due to such breaches.

Reporting Credits

(Reporting by Yadarisa Shabong in Bengaluru and James Davey in London; Editing by Vijay Kishore and William James)

Key Takeaways

  • The breach occurred via a third‑party notification tool: on October 6, customers received a rogue “ASOS hacked” in‑app notification linked to a Telegram extortion channel; ASOS says personal data (names, contacts) “may have been accessed,” but payment cards and passwords likely weren’t (itv.com).
  • ASOS responded by locking down affected platforms, confirming website and app functionality was unaffected, and is collaborating with the National Cyber Security Centre and law enforcement; cyber‑security insurance is in place (itv.com).
  • Shares initially dropped over 10% following the alert but later partially recovered; this incident highlights rising social‑engineering threats and risks linked to third‑party communication systems in retail (itv.com)

References

Frequently Asked Questions

What information was accessed in the ASOS cyber hack?
The breach exposed customer names and contact details, along with certain non-personal account related information.
Were customer payment details or passwords compromised during the cyber attack?
No, ASOS confirmed that no payment card information or account passwords were accessed.
How did the ASOS cyber breach occur?
An unauthorized party gained access to an employee account by impersonating a trusted contact and obtaining login credentials.
Is it safe to use the ASOS website and app after the hack?
Yes, ASOS stated that the website and app were secure throughout and remain safe to use.
What steps has ASOS taken following the cybersecurity breach?
ASOS locked down the affected platforms immediately and is working with law enforcement and regulatory authorities.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category