Asos customers told online retailer ‘hacked’ in phone alert

Asos customers told online retailer ‘hacked’ in phone alert

Thousands of Asos customers have been sent a phone alert saying the retailer has been hacked.Customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account.The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.Screengrab of the mobile phone message sent to customers (PA)PA MediaShares in the company tumbled by more than 10% on Tuesday morning as a result.The company has been contacted for comment.The alleged hack refers to cloud firm Snowflake, which stores data for many major companies.It has been the reported subject of a number of data breaches in recent years, including an attack on Ticketmaster which saw customer details stolen.Asos, which also owns brands including Topshop and Miss Selfridge, has 17 million customers globally.The UK is the group’s largest market, representing 49% of all revenues in the first half of the latest financial year.The fast fashion firm is currently undergoing a major turnaround programme in a bid to halt declining sales and return to profit.It comes after raft of UK retailers were targeted by cyber attackers over the past two years, including Marks & Spencer and Harrods.Marijus Briedis, chief technology officer at NordVPN, said: “This is an unusually brazen and threatening message.“The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.“What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.”Cyber expert Rob Demain, chief executive of e2e-assure, said it was unclear if the claimed Snowflake hack was real, “because we only have the attacker’s word for it”.Read MoreHe said: “The concerning thing for customers is that they received the threat through a channel they already trusted.“While unconfirmed, one possibility is that the compromise is confined to the customer engagement or marketing systems connected to Asos.“If the attackers only accessed that layer, it could explain the app notifications, but doesn’t prove any access to the wider retail infrastructure or the claimed data theft.“The architecture of how Asos connects to customer data illustrates the wider risk – marketing systems connect valuable customer information with the ability to send messages under the retailer’s name.”

Original Source

Read the full article at Standard →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.