Asos hackers duped employee to access customer personal data
Summarised from 7 outlets · 10 reports · Updated 8 Oct, 11:44 · Archive
Asos said an unauthorised party impersonated a trusted contact to gain employee login credentials and accessed customer personal information including names and contact details.
On Tuesday morning, Asos customers received a push notification on the retailer's mobile app claiming the company had been hacked. The message, which directed users to a Telegram account, read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification triggered immediate concern among Asos' 16.5 million customers and caused the London-listed company's share price to fall more than 13 per cent.
Asos initially said it had found no compromise of its platform and urged customers to ignore the notification. However, after undertaking a detailed investigation over the following 48 hours, the company issued a fuller update on Thursday morning. Asos said an unauthorised party had gained access to an employee account by impersonating a trusted contact to obtain login credentials. This technique is known as social engineering.
The attacker then used those credentials to access information on certain third-party platforms used by Asos. The company said it immediately locked down the affected platforms to prevent further activity and prevent additional information from being accessed.
Asos confirmed that the unauthorised party accessed some personal information, including names and contact details, as well as "certain non-personal account-related information." However, the company stressed that payment card information and account passwords were not compromised, and that the Asos website and app were safe to use throughout the incident.
The company apologised for the "unauthorised notification" and the "uncertainty" it caused. In its Thursday email to customers, Asos said: "We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos."
Asos has referred the incident to law enforcement and regulatory authorities and said it is working with both internal and external cyber experts. The company told customers there was no action they needed to take on their accounts but advised them to remain cautious of unexpected messages or calls claiming to be from Asos. It added: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
The company said that once its investigation is complete, it will contact customers directly where it believes additional information, support or action may be required. Asos stressed that it takes its responsibility to protect customer information seriously and has already taken additional steps to strengthen security controls.

How it is being reported
- ASOS issues update on cyber attack - everything customers need to knowFashion giant ASOS has urged customers to "remain alert" as it reveals what customer details may have been stolen in cyber attackThe Mirror · 8 Oct, 11:58
- Asos hackers 'in possession of detailed profiles of potentially millions of customers'The company has given an update after the hack earlier this week amid revelations the breach went beyond what was previously thought to be 'basic contact details'.Daily Mail · 8 Oct, 11:37
- Asos says customer data accessed by hacker posing as trusted contactCustomers are told payment details and passwords were not compromised when employee account was breached Business live – live updates Hackers gained access to Asos customer names and contact details by impersonating a “trusted contact” to gain access to one of its employee’s accounts, the retailer has said. Thousands of users of the online fashion seller’s app received a notification on Tuesday titled “Asos hacked” with a link to the Telegram messaging service, sending its shares diving by about 10%. Continue reading...The Guardian · 8 Oct, 11:35
- Asos says ‘unauthorised party’ impersonated contact to gain log-in detailsCustomers received a phone alert on Tuesday saying the retailer had been hacked.Evening Standard · 8 Oct, 11:31
- Asos warns customers to be vigilant of ‘unexpected calls’ after ‘hack’'We will never ask you to share passwords.'Metro · 8 Oct, 11:28
- Asos warns hack was worse than thought and customers’ personal information at riskCyber attackers impersonated a ‘trusted contact’ and broke into shop’s systemsIndependent Tech · 8 Oct, 11:26
- Asos says ‘unauthorised party’ impersonated contact to gain log-in detailsCustomers received a phone alert on Tuesday saying the retailer had been hacked.Evening Standard · 8 Oct, 11:08
- Asos says ‘unauthorised party’ impersonated contact to gain log-in detailsCustomers received a phone alert on Tuesday saying the retailer had been hacked.Independent Tech · 8 Oct, 11:08
- ASOS confirms personal details were accessed in hack update as retailer issues apologyASOS confirms unauthorised party gained ‘access to some personal information, including names and contact details’Evening Standard · 8 Oct, 11:08
- Asos hackers duped employee in data breachThe hackers behind a threat to leak Asos customer data duped an employee by posing as a “trusted contact,” the fast-fashion group has said. An unknown group shocked Asos’ millions of customers on Tuesday when they published a push notification on the online retailer’s app, claiming to have hacked into the company and threatening a [...]City AM · 8 Oct, 11:01
In this story: Asos · Telegram · Snowflake · London
This summary was written by AI from the headlines and standfirsts above, and states as fact only what at least two outlets report. How we use AI · Report a problem
Comments (0)