Asos has told customers to “remain cautious” over unexpected messages or calls claiming to be from the retailer, after an “unauthorised party” accessed some personal data. The fast fashion business confirmed the breach in an email to customers on Thursday morning (October 8), following a mobile app notification on Tuesday titled “Asos hacked”.
How the breach happened
Asos said it has undertaken a detailed investigation over the past 48 hours and found that the “unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials”. The party then used the credentials to access information on third-party platforms used by Asos.
Affected platforms were immediately locked down, but Asos said the attacker gained access to some personal data, including names and contact details. The attacker also accessed “certain non-personal account-related information”, Asos said.
What customers need to know
Asos stressed that no payment card information or account passwords were accessed. The Asos website and app were safe to use throughout the incident and “remain safe” to use, the firm said.
However, the company urged customers to remain vigilant. It said: “There is no action you need to take on your account. However, please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
Investigation and next steps
Asos added that it has already taken steps to strengthen its security controls and will continue with its full investigation. The email to customers came after BBC News said it had been contacted by cyber criminals claiming that the breach affected customer names, addresses, phone numbers, emails and customer numbers.
The notification message sent out by cyber attackers referred to cloud firm Snowflake, which stores data for many major companies. Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message.