
Asos has warned shoppers to be wary of any ‘unexpected’ phone calls after being sent a push alert saying the fashion giant had been ‘hacked’.
Personal information, such as names and contact details, may have been accessed, according to both Asos and the purported hackers.
But Asos, which has 16.5million customers, told them in an email sent this morning that payment and account information was not nabbed.
The BBC reports that the data includes names, addresses, phone numbers, emails and even what they search on the website, like ‘Asos petite’.
Asos’ email, seen by , said: We’re sorry for the unauthorised notification some of you received on 6 October and any uncertainty this caused.’
Asos said that initial findings from its ongoing investigation found that an ‘unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials’.
‘Those credentials were then used to access information on certain third-party platforms used by Asos.’

Such a swindle is called a ‘social engineering scam’, experts say, where people gain a person’s trust to get personal and financial information.
Asos said that the third party also got access to ‘certain non-personal account-related information’ but did not elaborate.
Asos’ email continued: ‘There is no action you need to take on your account.
‘However, please remain cautious of unexpected messages or calls claiming to be from ASOS.
‘We will never ask you to share passwords, security codes or payment details through an unsolicited message or call. You can find more information and advice here.’
Experts told that criminals could be masquerading as Asos to exploit customer worries about their data being exposed.

Texts about resetting passwords may end with a phone call and the scammer asking to confirm the victim’s card details or login.
Some look-alike texts or emails might include links to websites that install shady software called malware, which steals users’ personal details.
Tomas Stamulis, chief security officer at the cybersecurity software company Surfshark, says: ‘Customers need to be wary of any communications from banks and credit card companies offering to protect accounts following the attack, as it could well be scammers trying to feed on the fear.
‘If you are worried that you may have been impacted, change your passwords and keep a close eye on your accounts for any suspicious activity.
‘If you spot anything suspicious, get in touch with your providers proactively using the verified numbers on their websites.’
Asos said in a Q&A about the notification that it is not asking users to reset their passwords and is not sending out app notifications.
Get in touch with our news team by emailing us at webnews@metro.co.uk.
MORE: The best supermarket fashion buys under £60 from M&S, Tesco, Asda and Sainsbury’s
MORE: This simple switch can ease back pain — as long as you’re prepared to feel like a ‘loser’
MORE: Barrel-leg jeans, Harrington jackets and chunky knits dominate Topman’s new collection