
Key Takeaways
- Earlier this week, UK shoppers who had the ASOS app installed received a notification through it, from a hacking group that claimed to have compromised the brand’s third party data cloud. Yesterday, the scope of the breach was revealed to contain more than the personal contact details originally disclosed, including individual search histories and personalisation levers.
- As with the recent spate of retail-focused cybersecurity incidents, the group claiming responsibility obtained access to ASOS’ data through external systems and social engineering rather than direct intrusion into first party software. And while AI is involved in the brand’s personalisation pipeline, this does not seem to have been an AI-aided attack.
- Brands have continued to turn to personalisation platforms and strategies to enhance their customer engagement, creating new utility for personal data that then, in turn, creates a greater incentive to capture and retain that data – extending the industry’s risk surface over time. Hacks like the one ASOS is facing, and viral stories like Amazon’s more benign profile-building, bring that risk back into the consumer consciousness.
The Interline doesn’t like to generalise, but if you’re a frequent purchaser of fast fashion, you’re probably accustomed to getting a notification or two from the biggest names in that segment. No ASOS shopper, though, expected the ping they received this Tuesday, which came from the brand’s official iOS app, but which was signed off by a previously-unknown hacking group calling itself Xuanyewen.
That notification warned users that the brand’s systems had been hacked, and contained a message explicitly for ASOS’s IT team, and its data protection officer, claiming that the company’s Snowflake datastore had been compromised, and that the group would leak the stolen information unless the company engaged with it in a non-specified way.
ASOS confirmed the unauthorised notification later that day, in a regulatory announcement (part of its obligations as a listed company on the London Stock Exchange) but was reserved about where it originated, saying only that “third-party platforms that we use to communicate with customers” had been the subject of unauthorised access. On Thursday, ASOS told customers, via email, that an attacker had obtained an employee’s login credentials by impersonating a trusted contact, and had then used those credentials to sign into a third-party software vendor’s platform, which reporting suggests was Simon AI, an “agentic marketing” and personalisation platform (now part of “experience optimisation platform” Monetate, as of July).
The BBC, which received a sample of the extracted data from the attackers at roughly the same time, then reported that names, addresses, phone numbers, emails, customer numbers, and dates of birth were all in the dataset.
These are common datapoints that represent low-hanging fruit for cybercriminals, and for many customers the knowledge that their basic details had leaked would probably, in isolation, have elicited a resigned shrug. UK residents in particular have recently been inundated with thefts of personally identifiable information from major service providers, including the release of nearly 9 million sets of names, numbers, car registration plate details and WiFi logs, stolen from one of the country’s biggest airport groups last month.
UK retail, too, has become a bit of a playground for hackers in the last eighteen months. Earlier this summer, The Interline published a round-up of cybersecurity incidents in our industry, and urged companies to take the risks of AI-assisted hacking more seriously in the wake of the OpenAI / Hugging Face incident. And while this week’s breach was not, by all accounts, aided or engineered by AI, it remains an AI story because the systems involved are agentic in nature, and because the kind of information contained in the data cloud was destined to become fuel for AI-driven audience segmentation and personalisation.
Which is where the most important turn in this story comes in. As we’ve established, leaking people’s emails is nothing new, but the same BBC review of the data-in-play revealed that it also contained search histories and terms. It isn’t clear at this point whether those searches are directly associated with names and contact records, or whether they represent more of a firehose of query content unanchored to personal details. But The Interline would not be surprised if the data was all linked, because capturing those kind of behavioural indicators, and combining them with existing CRM profiles, is both exactly what Simon AI does, and is also the broad pattern behind a model of advertising and engagement that essentially every major brand is pursuing.
There’s limited utility in trying to peel apart ASOS’s direct pipeline for segmentation and personalisation, but even a bit of cursory research reveals a shape and scope that will look very familiar to other brands and retailers. In a case study published by Simon AI last year, which documents ASOS’s communications and marketing setup, Snowflake provides an underlying cloud data platform that all manner of different customer shopping activity data (and presumably wider business data as well) goes into. This is pretty universal: Snowflake is sufficiently large that it was, at least at one point, basically synonymous with the idea of data lakes, warehouses, lakehouses, and other labels for the general and ubiquitous practice of capturing non-normalised “big data” with the ambition to figure out how to extract new value from it later.
In this instance, according to that case study, that shopping activity was then parsed and assembled into segments and profiles using Simon AI, allowing the marketing team to build audiences of different levels of granularity. An integration to another solution (customer engagement platform Braze) then ran cross-channel communications campaigns against those audiences.
This, presumably, was how the hacking group was able to trigger a notification for the entire ASOS cohort. And, notably, it doesn’t actually provide any evidence that Snowflake itself was compromised. In practice, while the distinction probably matters very little to consumers receiving a scary notification, it was a separate AI personalisation and communication stack built on top of that data cloud that was apparently compromised.
For those consumers, though, this will all feel like retail is still making itself an easy target. This is, after all, the first instance that The Interline is aware of where a brand’s own communications infrastructure has been turned against it this directly. But right as that might feel in the open market (and a 13% short-term drop suggested that the impact was felt, even if ASOS overall has had a banner year, with operating earnings up more than a quarter as per guidance released just a fortnight ago) it’s important for both consumers and brands to recognise the difference between cybersecurity risk from systems and data, and the same risk from social engineering.
When we examined advanced persistence and the market for fear, earlier this summer, we argued that “the primary attack vectors for brands will likely remain soft social targets across the extended vendor and partner network.” This is validation of that framing, and the simplest analogy for it is the idea that you can secure your house with the best lock on the market, but if you leave a key with a neighbour then someone with enough time and persistence can either trick that neighbour, or just hit them with a hammer until they give up the spare.
Before you read on...
Our weekly news analysis will always be available to read here at The Interline, but you can get it (along with notifications for new podcast episodes, events, and more) in your inbox by signing up to our mailing list.
Whatever the vector, though, none of this addresses the question of why ASOS would hold that query and search history to begin with – or why any other brand looking to assess a range of potential metrics, or to try similar techniques for personalisation, would do the same. Because the more of it they collect, the more of it there is for bad actors to exploit if and when they are able to find a way in.
The simplest answer is that personalisation is just big business. In a separate ASOS case study, Simon AI claims it helped create $77.5 million in incremental revenue by combining data that was previously separate, coordinating communications across channels, and serving up relevant recommendations in response to shopping activity. This kind of behavioural triggering is common in modern online retail, and is the engine behind both simple conditions like a person leaving an item in their cart, and more complex ones like annual occasionwear purchasing patterns.
This is where another story from this week becomes relevant. It starts somewhere considerably less threatening than an extortion demand, but it ends in similar realisations for both retailers and consumers. For the former, it’s a reminder that the data they hold, and use for personalisation, can quickly turn against them. For the latter, it’s further, easier-to-digest evidence that the places they shop have more than likely been building detailed profiles of them for years, well before any of the current wave of AI-assisted personalisation became possible.
This week, TechCrunch reported on a viral social story of an Amazon shopper discovering that the company’s “About You” profile of her included the conclusion that she had “flat buttocks”. This was more than likely a residual datapoint created when she purchased shapewear, but it nevertheless made for a social media moment that put Amazon in a bad light – despite the fact that the company published controls for its About You feature back in May of this year.
This is an easy story to laugh at, because it anthropomorphises the same feature set we’ve been talking about so far. Amazon itself is, obviously, not setting out to appraise anyone’s ass, but that datapoint still serves as evidence of the “capture every possible signal” mentality behind personalisation.
The trouble here is twofold.
First, buying signals are not always a good proxy for real intent. Everyone reading this has probably experienced the blunt approach that many retailers take to recommendations, where buying from a category once means being sold further items from it indefinitely. Amazon, again, is the source of a lot of humour here, because its algorithm has, in the past, lacked precisely that sort of nuance. Buying a screwdriver seemed to set an internal flag that you were some kind of tool-hoarder, rather than making the more likely inference that you had a job to do, and that you were all set for screwing-things-in henceforth.
Second: buying signals are not forever. This is especially true in an era where wide availability of GLP-1s (Ozempic et al) are changing the timeframe within which consumers’ bodies can change, and driving more people back to physical stores to rediscover their current size preferences. Someone who searched for plus-size styles a year or less ago might now be in a completely different bracket, making it not just a data-minimisation risk to hold that kind of signal long-term, but also potentially a detriment to the very goal that gathering the data was intended to serve.
In both instances, the solution is not a breezy one for brands to consider. The decision to capture, hold, and use data spans both a network of third party providers and a broad spectrum of different in-house disciplines. The responsibility of how those datapoints are then retained, used, updated, and shared with third party processes needs, as a result, to become the responsibility of a dedicated data protection officer or consumer advocate – as well as becoming the subject of a formal request process that allows consumers to inspect, challenge, and request deletion of the things a business believes it knows about them.
Fashion, clearly, is bullish on personalisation. And the studies suggest that the value of granular, or even individualised, segmentation is measurable. But every step taken in the direction of better knowing your customers is also a step towards increasing the responsibility you have to manage everyone’s risk.
Social engineering might remain the foremost vector for the near future, but there is, almost inevitably, a moment coming where interactions between AI agents (either innocuous, or kicked-off by malicious actors) will reveal just how much retailers and brands really know about shoppers, and what they’re doing with that information. For consumers, that bargain feels reasonable when the output is better engagement, but it won’t take much more for public opinion to tip the other way.
