Online fashion retailer Asos has issued a new warning to its customers, revealing that cyber criminals have obtained extensive personal data profiles following a recent security breach. The updated advisory comes after investigative journalists contacted the company with evidence provided directly by the hackers, proving that the incident involved far more sensitive information than initially disclosed.

The compromised information includes full names, home addresses, phone numbers, email addresses, and unique customer identification numbers. Furthermore, the stolen data encompasses detailed search histories from the platform, revealing specific stylistic preferences and product searches made by individual users. Security experts warn that this granular level of personal information significantly increases the risk of targeted fraud, as malicious actors can leverage these search habits to craft convincing phishing emails and deceptive phone calls.

While the retailer has not disclosed the exact number of individuals affected, the security incident originally gained international attention when unauthorized notifications were broadcast directly through the company's mobile application to millions of users. Shortly after the alert, the business informed market regulators and the London Stock Exchange that an outside party had gained unauthorized access to basic user contact details.

In its subsequent communications to the affected customer base, the fashion platform confirmed that comprehensive data dossiers had been exfiltrated from its systems. However, the company emphasized that core financial credentials, such as credit card information and account passwords, remained secure and untouched during the cyber attack.

Representatives for the retail firm have advised all users to exercise heightened vigilance regarding unsolicited communications. Consumers are being urged to remain skeptical of unexpected telephone calls, text messages, or emails purporting to originate from the brand, particularly those attempting to verify account details. The corporate entity reiterated that it will never request sensitive security codes, passwords, or payment information through unsolicited channels.

Reporting based on coverage first published by BBC News. Read the original report at BBC News.