ASOS says stolen credentials exposed customer data
ASOS said an attacker used stolen employee credentials to access customer information, including names, contact details and website search histories, through third-party platforms. The online retailer said payment card details and account passwords were not accessed, and it has not confirmed how many customers were affected. In an update to customers on October 8, ASOS said the attacker impersonated a trusted contact to obtain an employee’s login credentials. The credentials were then used to access information on platforms used by the company, it said. ASOS described the incident as involving certain third-party platforms and said it had locked down the affected systems. The information accessed included names, email and delivery addresses, phone numbers and customer numbers, according to the company’s customer update. It also included non-personal account-related information, which reporting about a data sample supplied by the purported attacker indicated included recent searches made on the ASOS website. Examples included clothing and brand queries. The BBC reported receiving a sample from the purported attacker.