news.today
Hello · Register today | LoginHello · My Account[—] [31]
Business

Asos hackers duped employee to access customer personal data

Summarised from 7 outlets · 10 reports · Updated 8 Oct, 11:44 · Archive

Asos said an unauthorised party impersonated a trusted contact to gain employee login credentials and accessed customer personal information including names and contact details.

On Tuesday morning, Asos customers received a push notification on the retailer's mobile app claiming the company had been hacked. The message, which directed users to a Telegram account, read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification triggered immediate concern among Asos' 16.5 million customers and caused the London-listed company's share price to fall more than 13 per cent.

Asos initially said it had found no compromise of its platform and urged customers to ignore the notification. However, after undertaking a detailed investigation over the following 48 hours, the company issued a fuller update on Thursday morning. Asos said an unauthorised party had gained access to an employee account by impersonating a trusted contact to obtain login credentials. This technique is known as social engineering.

The attacker then used those credentials to access information on certain third-party platforms used by Asos. The company said it immediately locked down the affected platforms to prevent further activity and prevent additional information from being accessed.

Asos confirmed that the unauthorised party accessed some personal information, including names and contact details, as well as "certain non-personal account-related information." However, the company stressed that payment card information and account passwords were not compromised, and that the Asos website and app were safe to use throughout the incident.

The company apologised for the "unauthorised notification" and the "uncertainty" it caused. In its Thursday email to customers, Asos said: "We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos."

Asos has referred the incident to law enforcement and regulatory authorities and said it is working with both internal and external cyber experts. The company told customers there was no action they needed to take on their accounts but advised them to remain cautious of unexpected messages or calls claiming to be from Asos. It added: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."

The company said that once its investigation is complete, it will contact customers directly where it believes additional information, support or action may be required. Asos stressed that it takes its responsibility to protect customer information seriously and has already taken additional steps to strengthen security controls.

Asos hackers duped employee to access customer personal data
Image: The Mirror

Comments (0)

How it is being reported

In this story: Asos · Telegram · Snowflake · London

This summary was written by AI from the headlines and standfirsts above, and states as fact only what at least two outlets report. How we use AI · Report a problem