Asos has revealed that hackers accessed more extensive customer data than initially disclosed, including detailed user profiles and website search history. The update comes after the BBC was contacted by cyber criminals claiming the breach extended beyond basic contact details.

Previously, Asos had informed customers and shareholders that the breach, which occurred earlier this week, might have resulted in the access of names, email addresses, and phone numbers. However, cyber criminals provided the BBC with a sample of stolen data indicating that comprehensive profiles were compromised.

This newly revealed data includes customer names, addresses, phone numbers, emails, and customer numbers. Crucially, it also contains records of specific searches users made on the Asos website, such as terms like "reclaimed vintage," "glamorous wide fit," and "Asos petite." This level of detail could enable scammers to craft more convincing phishing attacks or impersonation scams.

Asos confirmed in an email to customers that data profiles were taken but stated that no bank details or passwords were accessed. The company warned customers to remain cautious of unexpected messages or calls claiming to be from Asos, emphasizing that they would never request passwords, security codes, or payment details via unsolicited communication.

The breach gained global attention on Tuesday when cyber criminals used Asos's own app system to send a pop-up notification to potentially millions of users. Asos later confirmed to the London Stock Exchange that an unauthorized third party had sent the notification and that basic personal information may have been accessed.

The cyber criminals, who identified themselves as Xuanyewen, claimed to have gained access to the data through a platform called Simon AI, which is built on top of Snowflake, a data storage and analysis company. Snowflake has previously stated that its platform had not been breached. Asos explained that hackers gained access by impersonating a trusted contact to obtain the login credentials for an unnamed service used by an Asos employee.

Asos stated it is continuing its investigation and will contact customers directly if additional information, support, or action is required. The company has advised customers that no immediate action is necessary. However, cybersecurity experts are recommending that users change their passwords as a precautionary measure and remain vigilant for any suspicious activity, particularly unsolicited requests to share or change passwords, as passwords themselves were not believed to be compromised.

The scale of the breach and the full extent of the data compromised are still under investigation by Asos.