Asos customers told 'hacked' in phone alert, shares tumble 10%
Asos customers told 'hacked' in phone alert; shares tumble 10%

Thousands of Asos customers received a mobile app notification on Tuesday titled “Asos hacked”, which directed them to a Telegram account. The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.

Shares tumble after alert

Shares in the company tumbled by more than 10% on Tuesday morning as a result. The company has been contacted for comment.

The alleged hack refers to cloud firm Snowflake, which stores data for many major companies. It has been the reported subject of a number of data breaches in recent years, including an attack on Ticketmaster which saw customer details stolen.

Asos customer base and market

Asos, which also owns brands including Topshop and Miss Selfridge, has 17 million customers globally. The UK is the group’s largest market, representing 49% of all revenues in the first half of the latest financial year.

The fast fashion firm is currently undergoing a major turnaround programme in a bid to halt declining sales and return to profit. It comes after a raft of UK retailers were targeted by cyber attackers over the past two years, including Marks & Spencer and Harrods.

Expert reactions

Marijus Briedis, chief technology officer at NordVPN, said: “This is an unusually brazen and threatening message.

“The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.

“What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.”

Cyber expert Rob Demain, chief executive of e2e-assure, said it was unclear if the claimed Snowflake hack was real, “because we only have the attacker’s word for it”.

He said: “The concerning thing for customers is that they received the threat through a channel they already trusted.

“While unconfirmed, one possibility is that the compromise is confined to the customer engagement or marketing systems connected to Asos.

“If the attackers only accessed that layer, it could explain the app notifications, but doesn’t prove any access to the wider retail infrastructure or the claimed data theft.

“The architecture of how Asos connects to customer data illustrates the wider risk – marketing systems connect valuable customer information with the ability to send messages under the retailer’s name.”