Asos customers told online retailer ‘hacked’ in phone alert

Asos customers told online retailer ‘hacked’ in phone alert

Thousands of Asos customers have been sent a phone alert saying the retailer has been hacked.Customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account.The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.Shares in the company tumbled by more than 10% on Tuesday morning as a result.Screengrab of the mobile phone message sent to customers (PA)PA MediaThe company has been contacted for comment.The alleged hack refers to cloud firm Snowflake, which stores data for many major companies.It has been the reported subject of a number of data breaches in recent years, including an attack on Ticketmaster which saw customer details stolen.Asos, which also owns brands including Topshop and Miss Selfridge, has 17 million customers globally.The UK is the group’s largest market, representing 49% of all revenues in the first half of the latest financial year.The fast fashion firm is currently undergoing a major turnaround programme in a bid to halt declining sales and return to profit.It comes after raft of UK retailers were targeted by cyber attackers over the past two years, including Marks & Spencer and Harrods.Marijus Briedis, chief technology officer at NordVPN, said: “This is an unusually brazen and threatening message.“The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.“What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.”Cyber expert Rob Demain, chief executive of e2e-assure, said it was unclear if the claimed Snowflake hack was real, “because we only have the attacker’s word for it”.He said: “The concerning thing for customers is that they received the threat through a channel they already trusted.“While unconfirmed, one possibility is that the compromise is confined to the customer engagement or marketing systems connected to Asos.“If the attackers only accessed that layer, it could explain the app notifications, but doesn’t prove any access to the wider retail infrastructure or the claimed data theft.Read More“The architecture of how Asos connects to customer data illustrates the wider risk – marketing systems connect valuable customer information with the ability to send messages under the retailer’s name.”The NCSC publishes guidance on its website for members of the public who are affected by data breaches.

Original Source

Read the full article at Standard →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.