Asos Data Breach Was Wider Than Initially Disclosed, BBC Reports
Hackers who breached Asos extracted more personal data than the retailer first admitted, the BBC has found after being contacted by the cyber criminals.
Online fashion retailer Asos has updated its breach disclosure after the BBC was contacted directly by the hackers responsible, who said the scope of stolen data extended well beyond the "basic contact details" the company had initially described to customers.
The development raises fresh questions about corporate transparency in the immediate aftermath of cyber incidents, where companies frequently issue cautious, minimizing statements before the full picture has been established. Asos's revised account follows direct communication between the BBC and the threat actors, an unusual circumstance that put the retailer in the position of having to revise its public narrative under media pressure.
Read more Chrysler Building Sold, Crown Restoration Plans Announced →
Data breaches that prove larger in scope than first reported can carry heightened regulatory and legal consequences for companies operating in the UK, where the Information Commissioner's Office has the authority to impose significant fines for failures to accurately and promptly notify affected individuals and regulators. Customers whose data has been compromised may face elevated risks of phishing, identity fraud, or credential-stuffing attacks, particularly if the stolen information goes beyond names and email addresses.
Asos has not yet detailed precisely what categories of additional personal information were accessed beyond the initial characterization of basic contact details. The BBC's reporting, prompted by the hackers making direct contact, suggests the full extent of the breach may still be emerging. Customers are advised to remain vigilant, monitor their accounts for suspicious activity, and consider changing passwords as a precaution.
Continue reading at BBC News.