Asos shoppers urged to stay vigilant after hacking alert
Asos shoppers urged to stay vigilant after hacking alert

Asos shoppers have been advised to stay vigilant after a ransom note appeared in the company's app, with the fashion giant confirming that customer names and contact details may have been accessed.

Yesterday morning, users received a push notification from the Asos app that read: 'Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' The message, addressed to the company's data protection officer and IT teams, was described by experts as a ransom note. It asked users to join a Telegram page, where the hackers claimed to have obtained 'customer information'.

What should Asos shoppers do?

Asos has said it is safe to browse on its app and that it has restricted access to its notification platforms while it investigates. A Q&A on the Asos website states: 'We are not currently asking customers to change their Asos account password or take any other action. If this changes, we will contact affected customers directly.'

However, Tomas Stamulis, chief security officer at digital privacy tool Surfshark, says shoppers should not do nothing. The hackers and Asos both said that payment card records or passwords were not compromised, but the breach may open the door for other criminals to try to obtain these details. Crooks may attempt phishing scams, posing as Asos to frighten people into clicking dodgy links in emails or texts.

'There is usually an increase in volume following an attack on a company like Asos because attackers know customers may be worried about their data being exposed,' Stamulis says. 'If you've clicked a suspicious notification or link, don't assume the worst, but act quickly. Close the page straight away and avoid entering any personal information, passwords or payment details.'

What to do if you clicked a dodgy link

If a link loads a blank webpage, it may have activated malware. 'If anything has downloaded or been installed, disconnect the device from the internet and run a full malware scan,' Stamulis adds. Alternatively, the link may lead to a spoofed Asos page asking for a password. If you entered details, change that password from a 'clean device', including your email log-in.

'Access to your inbox can give criminals a route into other services through password resets,' Stamulis says. 'Use a unique password for each account and enable two-factor authentication where possible.' Two-factor authentication adds a second step to the log-in process, such as a code sent by email or text, or an authenticator app. Some services allow passkeys stored on a device, locked behind a pin or biometric authorisation.

Stamulis advises keeping an eye out for emails about unfamiliar logins, password changes or transactions. 'Be particularly vigilant about unexpected calls, texts or emails offering to help with the issue, as scammers can use the situation to pose as a trusted company or support service and try to gather more information from you,' he says.

Experts call for clearer Asos communication

Aimee Speight, a communications expert and founder of Highland Consulting, says Asos should be giving this kind of advice. 'Asos confirmed names and contact details may have been accessed, which is a scammer's starter pack, yet there isn't a single line telling customers what to look out for,' she says. 'The most useful thing Asos can do is push a notification of its own: here's what happened, here's what to watch for, and we will never ask for your details by link.'

Asos shares tumbled by 14% on the London Stock Exchange after the notification was broadcast. Marty Bauer, e-commerce expert at marketing software firm Omnisend, says the incident may have damaged the 'trust' shoppers had in Asos. 'With Black Friday approaching, Asos will want existing customers to feel comfortable buying again,' Bauer says. 'If shoppers disengage from push notifications and email now, that is revenue the brand may find difficult to win back.'