Features Markets Alerts Brokers Pricing Live Demo Blog About Sign In Start Free →
Protecting your investment accounts online
PORTFOLIOTRACKR
Security & Privacy

Asos Breach Exposed Customer Data: Why Read-Only Access Matters

By James Whitfield · October 8, 2026 · 9 min read

On October 8, 2026, UK retailer Asos told customers that a hacker posing as a trusted contact accessed names, addresses, phone numbers and emails, though payment card data stayed safe. The breach is a reminder that the data you hand to an app matters as much as your money, and that read-only connections limit the damage when something goes wrong.

What happened in the Asos data breach?

On October 8, 2026, Asos warned customers that an attacker impersonated a trusted contact to gain access to its systems and view personal records. According to the company, the exposed data included names, postal addresses, phone numbers and email addresses, while payment card details were not compromised.

The attack vector matters here. This was not a brute-force hack of a password vault. It was social engineering, where someone convinced a human or a system that they were legitimate. That is the same tactic behind most modern financial scams, and it is far cheaper for an attacker than breaking encryption.

The lesson for investors is simple. Every service that holds your data is a potential leak point, and the ones that hold both your identity and your finances carry the highest stakes.

Why does a retail breach matter for your investment data?

A retail breach matters because the same stolen contact details feed directly into investment fraud. Once an attacker knows your name, email, phone number and address, they can craft a convincing message that looks like it comes from your broker, your bank or a tax authority.

Stolen contact data is the raw material for the scams investors actually fall for:

None of these require your password up front. They require trust, and leaked contact data manufactures that trust.

What is read-only broker access, and why does it protect you?

Read-only broker access is a connection that can see your holdings and prices but cannot place a trade, move cash or withdraw funds. A portfolio tracker with read-only access imports positions to display them; it has no permission to touch the account itself.

This is the single most important safeguard in portfolio-tracking security. If a tracker is ever breached, read-only access caps the damage: an attacker sees numbers, not a withdrawal button.

How PortfolioTrackr's broker connections work

Every broker connection in PortfolioTrackr is read-only. When you link an account, the tracker pulls your positions and balances to display them, and that is the full extent of the permission.

If you want the mechanics of linking an account step by step, our guide on how to connect your brokerage account to a portfolio tracker walks through it.

Do you even need to connect a broker to stay secure?

No. Connecting a broker is entirely optional in PortfolioTrackr, and the smallest attack surface of all is the one where no financial account is linked at all.

You can build and maintain a full portfolio without ever handing over a broker credential:

If you prefer tracking without any live link, our comparison of a portfolio tracker versus a spreadsheet shows what you gain and lose either way.

How does read-only access compare to full account access?

Read-only access limits a breach to visibility, while full trading access exposes your actual funds. The table below shows what each permission level can and cannot do if it falls into the wrong hands.

CapabilityRead-only accessFull trading accessManual entry only
See holdings and pricesYesYesYes (you enter them)
Place or cancel tradesNoYesNo
Withdraw or move cashNoYesNo
Damage if the tracker is breachedData exposure onlyPotential fund lossData exposure only

PortfolioTrackr never requests full trading access through any connection. The most sensitive action it can ever report is status against your own price levels, not a trade.

What privacy safeguards actually reduce your risk?

The safeguards that reduce your risk are the boring, structural ones: least-privilege access, strong authentication, and minimal data collection. A breach like Asos spreads because stolen contact data defeats weak login security elsewhere.

Turn on the right second factor

Use an authenticator-app code rather than SMS wherever you can. SMS can be intercepted through a SIM swap, which is exactly what leaked phone numbers enable. Our breakdown of SMS versus TOTP two-factor authentication explains why the difference is not cosmetic.

Keep sharing under control

When you share a portfolio, share it read-only so viewers see figures without any ability to change them. Our guide to sharing your portfolio read-only without losing control covers how to do this cleanly.

Know what alerts can and cannot reveal

PortfolioTrackr alerts are price levels only: Target 1, Target 2 and a stop-loss on a position, or a price above or below on a watchlist entry. Each level is checked once a minute while the market is open, and around the clock for crypto, and you hear within a minute of your level being hit.

What should an Asos customer who invests check right now?

If your details were in the Asos breach and you also invest, the useful move is to audit your own exposure to follow-on scams, not to touch any position. Checking is not the same as reacting in the market.

  1. Assume your contact details are public and treat any unexpected broker or bank message as suspect.
  2. Verify through the official app, never through a link or number sent to you.
  3. Switch SMS codes to an authenticator app on every financial account that allows it.
  4. Review every connected service and confirm each one is read-only or disconnect it.
  5. Watch for impersonation, the exact tactic Asos described, since attackers reuse what works, as the NEAR Intents exploit aftermath showed.

If you are comparing tools on their security posture, our real-data comparison of six portfolio trackers looks at how each one handles access and privacy.

The bottom line

The Asos breach exposed contact details, not payment cards, but leaked identity data is precisely what powers the next wave of investment scams. The structural fix is to minimise what any app can do on your behalf.

PortfolioTrackr keeps every broker connection read-only, lets you skip broker links entirely with manual, voice, CSV or screenshot entry, and never requests permission to trade or move your money. That design means a worst-case breach exposes figures, not funds, and your decisions stay entirely yours.

Track your portfolio in real time: free for 3 days

Live P&L across stocks, crypto, and global markets. WhatsApp and Telegram price alerts. AI trade import. Unified dividend tracking. No brokerage connection required.

Start Free Trial
Download on the App Store Get it on Google Play
See the live demo first →

Frequently asked questions

Was payment information stolen in the Asos data breach?

No. Asos said on October 8, 2026 that payment card details were not compromised. The attacker, posing as a trusted contact, accessed names, addresses, phone numbers and email addresses. That contact data still matters because it fuels phishing, SIM-swap and impersonation attempts against your financial accounts.

What does read-only broker access mean for a portfolio tracker?

Read-only broker access lets a tracker see your holdings and balances but not place trades, move cash or withdraw funds. If the tracker is ever breached, the exposure is limited to data visibility rather than fund loss. PortfolioTrackr uses read-only connections for every linked broker account.

Do I have to connect a broker to use PortfolioTrackr?

No. Connecting a broker is optional on every plan. You can track everything using manual entry, Smart Import by voice, text or screenshot, or bulk CSV import, all available on the free trial and Starter. Skipping the broker link gives you the smallest possible attack surface.

Is an authenticator app safer than SMS for two-factor authentication?

Yes. An authenticator-app code cannot be intercepted through a SIM swap, which leaked phone numbers make easier. SMS codes can be redirected to an attacker's device. For any financial account that offers it, an authenticator app is the stronger second factor against breach-driven account takeover.

How can investors protect their data after a company breach?

Assume your contact details are public, verify messages only through official apps, switch SMS codes to an authenticator app, and review every connected service to confirm it is read-only. Watch for impersonation, the tactic used against Asos, since attackers reuse what works across unrelated accounts.

James Whitfield
James Whitfield covers broker connections, data security and the mechanics of portfolio tracking at PortfolioTrackr: getting your positions in accurately and keeping them safe.
All articles by James →
Follow our market news on Google
Add PortfolioTrackr as a preferred source and Google will show you more of our articles in Top Stories.
Add as a preferred source on Google →