ASOS cyber attack: customer details may be stolen
ASOS cyber attack: customer details may be stolen

Online fashion giant ASOS has admitted hackers were able to get their hands on customers' personal information. The firm gave an update after the attack, as it urged its shoppers to "remain cautious". However, it sought to reassure them that whoever was behind the breach had not been able to access payment card information or passwords.

What we know so far

The attack on ASOS's systems emerged on Tuesday this week when customers received an app notification titled "Asos hacked", which directed them to the messaging app Telegram. The message read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The threat to the online retailer's data protection officer and IT teams referred to the cloud firm Snowflake, which stores data for major companies.

ASOS, which has 16.5 million customers, said names and contact details may have been accessed, but it did not believe payment card details or passwords were affected.

What is ASOS saying now

The company has given an update after carrying out an initial investigation into what happened. It says it discovered that an "unauthorised party" gained access to an ASOS employee's account by "impersonating a trusted contact" to obtain their log-in details. These were then used to get hold of information on a separate IT platform used by ASOS.

"The affected platforms were immediately locked down, ensuring that no further information could be accessed and a full investigation was launched with the support of both internal and external cyber experts," it said. "We are also working with the relevant law enforcement and regulatory authorities."

What customers need to know

ASOS confirmed earlier suspicions that hackers had accessed "some personal information" for customers, including names and contact details, as well as "non-personal related information", although it hasn't said what that is. The company has not revealed how many customers' details have been compromised.

However, it says that an internal investigation had found no evidence of payment card details being accessed, nor account passwords. It also insisted the ASOS website and app has been safe to use throughout.

What should customers do now

ASOS says they don't need to change anything on their account with the firm. However, it is urging them to "remain cautious of unexpected messages or calls claiming to be from ASOS." And it stresses: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."