Hackers who infiltrated fashion firm Asos's website are feared to have detailed profiles from millions of customers.The company has given an update after the hack earlier this week amid revelations the breach went beyond what was previously thought to be 'basic contact details'.Cyber-criminals behind the attack could now have access to shoppers' names, addresses, phone numbers, email addresses and past searches on the site. In a new email to consumers, Asos said: 'Please remain cautious of unexpected messages or calls claiming to be from Asos.'We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.'BBC News today told of being contacted by hackers who claimed they had access to extra information about Asos customers. Asos confirmed on Tuesday hackers could have accessed 'basic personal information' after customers received an 'unusually brazen' message threatening to leak their data.In a statement issued after the 'unauthorised' notification was sent, the firm said that it did not believe 'payment card details or passwords were impacted'. Millions of customers are feared to be affected by a cyber-hack of the fashion firm AsosMessages sent by the hackers to customers' phones said they had 'fully compromised the Snow flake instance', referring to the online platform that collects data, including that of customers. The notification included a threatening message to Asos: 'Engage with us or we will leak it'.It also contained a link to the hackers' Telegram channel, the 'Xuanye Group', that was only created the previous day.It is understood messages later appeared on that channel claiming that 'customer information is safe on our server' and 'it will not be touched for a designated period'.One message from the hackers is said to read: 'Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident.'The hackers had demanded a ransom payment from Asos in exchange for deleting customer information.It quoted a text from messaging app Telegram, saying: 'Our message is clear, and simple to recognise. The organisation must contact us or we will leak it [customers' data], that is what we said.'The 2-week period is intended for them to make contact, they know what happened.'The hackers said in an online notification: 'Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.'Snowflake is a cloud-based platform that firms use to store, process and analyse data and an 'instance' refers to a customer's individual environment on the platform.Shares in Asos, which also owns brands including Topshop and Miss Selfridge, fell by more than 9 per cent after reports of the hacking emerged.Cyber-security experts said the hackers' 'unusually brazen' notification was 'designed to whip up panic'.A statement was released by Asos on Tuesday in which the firm apologised to customers if they had received the 'unauthorised push notification'. In a further statement to the London Stock Exchange, it said: 'Asos can confirm that, at around 10am today, an unauthorised customer notification was sent to Asos customers.' 'We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.'We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.'Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.'Our website and app are operating as normal, with no current disruption to any aspects of our operations.'Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.'The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.'Katherine James, director of Snowflake's Europe, Middle East and Africa communications team, told the BBC: 'As soon as we became aware of the notification that is currently being reported, we began an investigation.'At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously.'The investigation is ongoing and we will provide further updates as soon as more information becomes available.'Asos says it has 17 million customers in 150 countries.Panicked customers reacted online to the 'crazy notification' and some said they had 'never deleted my payment methods so quick'.Marie Wilcox, VP of market strategy at cyber-security firm Binalyze, said: 'This notification was psychological warfare, designed to whip up panic. Attackers know that any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response.'Asos is legally obliged to tell customers if their data has been breached under the UK's data protection law.Kat Cereda, from consumer watchdog Which?, told the BBC this should be done 'without any undue delay' and the firm should 'explain the consequences and outline what steps they are going to be taking to protect you'. Britain is Asos's largest market, representing 49 per cent of all revenues in the first half of the latest financial year.The fast-fashion firm is undergoing a major turnaround programme to halt declining sales and return to profit.Mike Ashley's Frasers Group owns 29.26 per cent of Asos and is the firm's largest shareholder. Britain has been hit by several cyber attacks in recent months. In August, up to 1,000 charities, including Breast Cancer UK, English National Ballet and the Molly Rose Foundation, were targeted. Criminals targeted Beacon CRM, which provides customer management software to the charity sector.It is thought the firm mistakenly published an access key online that allowed hackers to copy its databases.Meanwhile, M&S and Co-op were targeted by a cyber-attack in the spring and summer of last year. Notorious hacker group Scattered Spider was linked to the hack that left shelves empty for weeks and forced M&S to stop accepting all online orders and payments.READ MORE: Asos confirms hack warning 'basic personal information' may have been accessed after customers receive 'unauthorised notification' on app
Asos hackers 'in possession of detailed profiles of potentially millions of customers'
Full Article
Original Source
Read the full article at Dailymail →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.