ASOS has reportedly been hacked, with thousands of customers receiving an eerie notification on Tuesday morning. The message read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
Warning to customers
A warning message on the app said: "If you received an unauthorised ASOS push notification earlier today, please disregard the notification and do not click or engage with the external third-party link it contained. Our teams have taken immediate action and are investigating. Customers can continue to shop with ASOS as normal."
In a statement released through the London Stock Exchange, the company said: "ASOS can confirm that, at around 10am today, an unauthorised customer notification was sent to ASOS customers. We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers."
Investigation and impact
The statement continued: "We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities. Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted."
It added: "Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate. The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading."