Asos has apologised to customers who received a phone alert saying the online retailer had been hacked. The fashion giant said it is investigating “unauthorised activity” involving a third-party platform and urged customers to disregard the notification and not click it or any links on it.
Investigation into unauthorised activity
The online retailer, which has 16.5 million customers, said personal information, such as names and contact details, “may have been accessed” in the incident. However, the company said it does not “believe that payment card information or account passwords, were impacted”.
In an email to customers on Tuesday evening, the firm said: “We’re sorry that you may have received an unauthorised push notification from us earlier today. Please disregard the notification and do not click or engage with the external third-party link it contained.”
Notification directed customers to Telegram
Customers received a mobile app notification earlier on Tuesday, titled “Asos hacked”, which directed them to a Telegram account. The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.
Later on Tuesday, the company confirmed that an “unauthorised customer notification” had been sent out through its mobile app. In a statement, the company said: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.
“Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”
NCSC support and Snowflake response
The National Cyber Security Centre (NCSC), a part of GCHQ, has offered Asos assistance. The notification message sent out by cyber attackers refers to cloud firm Snowflake, which stores data for many major companies.
Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message. “The investigation is ongoing and we will provide further updates as soon as more information becomes available,” a spokeswoman added.
Asos told shareholders it has cyber security insurance with a large provider and said it is “too early” to quantify any potential impact on its trading. Shares in the company fell by more than 10% on Tuesday as a result. The UK is the group’s largest market, representing 49% of all revenues in the first half of the latest financial year.
Broader impact and advice
The fast fashion firm is currently undergoing a major turnaround programme in a bid to halt declining sales and return to profit. It comes after a raft of UK retailers were targeted by cyber attackers over the past two years, including Marks & Spencer, Harrods and Jaguar Land Rover.
Dr Richard Horne, chief executive of the NCSC, said: “The unauthorised notification sent out to Asos customers has brought into the light how cyber incidents do not simply affect big business but can have repercussions for individuals much more widely too.
“The NCSC has been in contact with Asos today to offer our support as the company investigates what has taken place.
“Individuals who received the notification should not click on any suspicious links and should stay vigilant to suspicious messages that may seek to take advantage of news of the breach.
“If you are worried about your personal data being impacted, we recommend following the advice set out at ncsc.gov.uk to help stay safe online.”