Online fashion retailer ASOS has issued a statement following an alleged hack earlier today (October 6). The fashion giant said it is investigating “unauthorised activity involving third-party platforms” used to communicate with its customers, whose basic personal details may have been accessed.
Threatening notification sent to customers
It follows reports that ASOS had been hacked after customers received a threatening push notification. The notification appeared just before 10am this morning, seemingly threatening owners of a 'leak' if they do not engage with those who are responsible. The message reads: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
It is understood that the National Cyber Security Centre (NCSC), a part of GCHQ, has offered ASOS assistance. The alleged hack refers to cloud firm Snowflake, which stores data for many major companies.
Investigation and response
ASOS confirmed that an "unauthorised customer notification" was sent at around 10am this morning. "We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers," it said in a statement.
The retailer said it immediately restricted access to the notification platforms and is working with specialists and relevant authorities. It added: "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.
"Our website and app are operating as normal, with no current disruption to any aspects of our operations.
"Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.
"The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading."
Market impact and customer advice
Shares in the company tumbled by more than 10% on Tuesday morning as a result of the hack. Experts claim that it can take days to weeks to contain a cyber hack.
Customers were warned against clicking any unexpected messages, even if they do look convincing and instead should go directly to the ASOS app or website. Chief Technology Officer at NordVPN, Marijus Briedis, advised customers to change their passwords if they have used the same password on other sites as they have for ASOS.