Online fashion retailer Asos has disclosed that a recent cyber-attack compromised millions of customers' personal details, including names, home addresses, email addresses, phone numbers, and recent search histories. The security breach came to light after users of the company's app received an unexpected push notification titled Asos hacked that directed them to a Telegram messaging channel. Following a 48-hour internal investigation, Asos confirmed that an unauthorized third party had accessed basic customer information stored on platforms managed by an external service provider.

According to the retailer, the intruders gained entry after impersonating a trusted contact to compromise a staff member's login credentials. The stolen credentials allowed the attackers to access databases belonging to a third-party platform utilized by the company. Asos stated that the impacted systems were swiftly secured to prevent further unauthorized access, and external cybersecurity specialists were brought in to assist with the inquiry alongside law enforcement and regulatory agencies.

The compromised information includes non-personal account data such as users' recent app search histories, which featured specific product queries typed into the platform. However, Asos assured customers that financial data such as payment card details and account passwords remained secure and were not accessed during the incident.

Cybersecurity professionals have expressed concern over the scope of the exposed data, noting that the inclusion of search histories could aid malicious actors. Analysts pointed out that because the retailer frequently sends promotional reminders about searched items, criminals could weaponize this information to craft convincing phishing emails that closely mimic legitimate company communications.

Consumer advocacy groups and security experts have urged shoppers to remain vigilant against unexpected phone calls, text messages, and emails over the coming weeks. Individuals who receive suspicious communications are advised to terminate the contact immediately and reach out to organizations through official, verified channels rather than responding directly to unsolicited prompts.

The incident follows a string of high-profile cyber disruptions affecting major British retailers over the past year, highlighting ongoing vulnerabilities in supply chains and third-party vendor networks. Asos stated that it has implemented additional security controls and pledged to notify affected customers directly if further individual action or support becomes necessary.