ASOS Hackers Threaten to ‘Leak’ Shoppers’ Details: Company Warns Customers to ‘Remain Alert’

ASOS Hackers Threaten to ‘Leak’ Shoppers’ Details: Company Warns Customers to ‘Remain Alert’


ASOS has confirmed that hackers accessed third-party systems used to communicate with customers and stole personal information, including data beyond the names and contact details the retailer initially disclosed. The stolen information also included customers’ home addresses and searches on the ASOS website, BBC reported.

The breach became public on Oct. 6, when customers received a threatening notification through ASOS’s own app. The message claimed the attackers had compromised the retailer’s Snowflake environment and threatened to leak data unless ASOS engaged with them.

ASOS says it does not believe payment-card information or account passwords were affected. But shopping searches can reveal what customers are interested in, giving scammers details they can use to make fraudulent messages seem credible.

How the ASOS Breach Began

Around 10 a.m. on Oct. 6, customers received a push notification titled “ASOS hacked.” The message was addressed to ASOS’s data protection officer and IT team, claimed the attackers had fully compromised a Snowflake instance, and demanded engagement before the data was leaked. It also linked to a Telegram account.

ASOS told customers to disregard the notification and not click its link. TechCrunch reported that the attackers used the name Xuanye Group.

“An unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log-in credentials,” ASOS said in its Oct. 8 update. The credentials were then used to access information on third-party platforms. The incident involved third-party platforms holding information used to communicate with customers. ASOS has not said that its main website or app was broadly compromised.

What Data Was Exposed

ASOS initially said names and contact details may have been accessed. BBC reporting found that the sample included customers’ home addresses, phone numbers, email addresses, and website search queries, alongside other customer-profile information.

The reported search terms included “reclaimed vintage,” “glamorous wide fit” and “ASOS petite.” Malwarebytes’ Oct. 9 account of the BBC findings also listed dates of birth and details about when customers began using ASOS.

ASOS later told customers that detailed profiles potentially relating to millions of users had been obtained, according to BBC. The retailer has not published a verified count of affected customers, so its global customer base of about 17 million should not be mistaken for the confirmed size of the breach.

“There is no action you need to take on your account. However, please remain cautious of unexpected messages or calls claiming to be from Asos,” the retailer told customers. It added that it would never ask for passwords, security codes or payment details through unsolicited contact.

Why Snowflake Was Named

“We can confirm this issue did not in any way result from a vulnerability, weakness, flaw, or misconfiguration with the Snowflake service, platform, or internal environments, and was not caused by Snowflake,” a Snowflake spokesperson said.

“Our investigation has found no compromise of Snowflake’s platform,” Snowflake said in response to questions about the incident, according to BBC reporting. The reported access route points to credentials and connected services; it does not establish that Snowflake itself had a security flaw.

The app notification raises a separate question. Delivering a message through ASOS’s customer communication system required access to the notification infrastructure, which is distinct from the platform holding customer data. The precise route the attackers used to send the message has not been fully established in the reporting reviewed.

How to Protect Your ASOS Account

“If you are an ASOS customer, you should assume you are affected by this incident, even if you did not receive the unauthorised notification,” the National Cyber Security Centre said in its Oct. 6 alert. It also advised customers not to click suspicious links in push notifications, emails or messages.

Shopping searches could make the next wave of scams more convincing. A fraudulent message mentioning a style someone browsed, a delivery problem or a supposed refund may feel legitimate because it contains information the customer recognizes. That familiarity is not proof that the message came from ASOS.

ASOS has said it is not currently asking customers to change their passwords and will contact affected customers directly if further action is needed. Customers should not follow instructions in unsolicited messages claiming to be from the retailer. Instead, they should open the official ASOS app or type the retailer’s address into their browser to check for updates.

Changing a password may be sensible if it has been reused on other services, and customers should review account activity and enable two-step verification where available. They should never share passwords, payment details, or security codes in response to an unexpected message.



Source link

Posted in

Liam Redmond

As an editor at Forbes Europe, I specialize in exploring business innovations and entrepreneurial success stories. My passion lies in delivering impactful content that resonates with readers and sparks meaningful conversations.

Leave a Comment