Asos probes unauthorised activity after customers get hack alert
Asos probes unauthorised activity after customers get hack alert

Asos has said it is investigating “unauthorised activity” involving a third-party platform after customers were sent a phone alert saying the online retailer had been hacked.

The fashion giant, which has 16.5 million customers, said personal information, such as names and contact details, “may have been accessed” as a result. However, the company said it does not “believe that payment card information or account passwords, were impacted”.

Mobile app notification

Customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account. The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.

On Tuesday afternoon, the company confirmed that an “unauthorised customer notification” had been sent out through its mobile app.

Company statement

In a statement, the company said: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.

“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

“Our website and app are operating as normal, with no current disruption to any aspects of our operations.

“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”

Assistance and market impact

It is understood that the National Cyber Security Centre (NCSC), a part of GCHQ, has offered Asos assistance. The retailer told shareholders it has cyber security insurance with a large provider and said it is “too early” to quantify any potential impact on its trading.

Shares in the company fell by more than 10% on Tuesday as a result.