Asos investigating after ‘unauthorised’ app access leaves some customer data exposed
Asos says an unidentified third party accessed its app systems, potentially exposing basic customer contact details; the company says payment card data and passwords do not appear affected and its shares fell 11%.

Asos has opened an investigation after its app systems were accessed by an “unidentified third party,” the company said, following notifications to some shoppers that their data had been compromised.
The online fashion retailer said basic personal information — including names and contact details — may have been exposed. Asos added that it did not believe payment card records or customer passwords had been compromised.
Shoppers reported receiving a message claiming hackers had “fully compromised” Asos data, prompting the company to alert users and launch an inquiry into the incident. The suspected access affected the company’s app systems rather than its wider infrastructure, according to Asos.
Market reaction was swift: Asos’s shares fell about 11% after the company disclosed the issue.
Why the alert matters
The potential exposure of names and contact information raises risks such as targeted phishing, spam and identity-related scams, even if financial details appear safe. Customers often rely on retailers to protect stored contact details and to signal clearly when breaches occur; public disclosure and investigation can help limit further harm and guide users on protective steps.
Asos’s statement that passwords and payment card records do not appear to have been compromised is significant because those data types typically drive immediate fraud. Nonetheless, the company’s acknowledgement that some personal information may have been accessed underlines the growing challenge retailers face in securing customer data across apps and digital platforms.
What we know and what remains unclear
- Asos has confirmed an unauthorised access to its app systems and is investigating. This wording and the details above were provided by the company.
- The company said basic personal information, such as names and contact details, might have been accessed.
- Asos stated it did not believe payment card records or customer passwords were compromised.
- Some customers received notifications claiming that hackers had “fully compromised” Asos data.
- Shares in Asos fell roughly 11% after the disclosure.
The identity and motives of the unidentified third party behind the access have not been disclosed. Nor has Asos provided a detailed timeline of when the access occurred or how many customers might be affected. The company’s investigation is ongoing.
What customers should look for
Asos’s public update did not include prescriptive customer advice in the reports reviewed here, but users commonly are advised to be cautious of unexpected messages, to verify the sender before clicking links, and to monitor accounts for unusual activity. Because contact details may have been exposed, customers should be alert for unsolicited calls, emails or texts that seek further personal information.
Sources
This story was written from reports by these outlets. Read the originals:



