ASOS confirms personal details accessed in hack update as retailer issues apology
ASOS confirms personal details accessed in hack update

ASOS has confirmed that an unauthorised party gained access to personal information including names and contact details, following an investigation into a security incident that began with a suspicious push notification sent to customers on Tuesday morning.

The notification, which contained a link to a Telegram chat, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The company later said it had found “no compromise” of its platform and urged customers to ignore the notification and not click on links in the message.

Investigation findings

In an update sent to its 16.5 million customers on Thursday, ASOS apologised for the incident and “any uncertainty this caused”. The retailer explained that over the past 48 hours, an investigation had been underway into the incident.

“We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials. Those credentials were then used to access information on certain third-party platforms used by ASOS. The affected platforms were immediately locked down, ensuring that no further information could be accessed and a full investigation was launched with the support of both internal and external cyber experts. We are also working with the relevant law enforcement and regulatory authorities.”

Impact and customer guidance

ASOS confirmed that the unauthorised party gained “access to some personal information, including names and contact details, and certain non-personal account related information”. However, it confirmed that no payment card information or account passwords were accessed.

The retailer added that the website and app were safe to use throughout and continue to remain safe to use today. “There is no action you need to take on your account,” it stressed. “However, please remain cautious of unexpected messages or calls claiming to be from ASOS. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”

The investigation remains ongoing and the retailer said it will contact customers directly if additional action is required. Shares in ASOS fell more than 10% on Tuesday after the notification was sent, interrupting a strong run for the online fashion retailer, whose shares had nearly doubled over the past year.