Asos issues update after 'unauthorised party' gained access to customer details
Asos update after 'unauthorised party' accessed customer details

Asos has issued an update to shoppers after a threatening notification was sent to millions of customers earlier this week. In an email sent to customers on Thursday (8 October), the online fashion retailer said an "unauthorised party" gained access by impersonating a trusted contact to get log-in information, after customers received a phone alert saying that the retailer had been hacked.

Investigation findings

A spokesperson for the company told customers to "remain cautious" over unexpected messages or calls claiming to be from Asos. It comes after customers received a mobile app notification on Tuesday (6 October), titled "Asos hacked", which directed them to a Telegram account.

The correspondence seemingly threatened owners of a 'leak' if they did not engage with those who are responsible. Many customers who received their email feared their basic personal details may have been accessed.

What data was accessed

Asos said it has undertaken a detailed investigation over the past 48 hours, with assistance from the National Cyber Security Centre (NCSC). Together, they found an "unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials".

It said the party then used the credentials to access information on third-party platforms used by Asos. Affected platforms were immediately locked down but Asos said the attacker gained access to some personal data, including names and contact details.

Customer guidance

Those responsible for the hack were also able to access "certain non-personal account-related information", Asos said. However, it stressed that no payment card information or account passwords were accessed.

The Asos website and app were safe to use throughout the incident and "remain safe" to use, the firm said. However, the company urged customers to remain vigilant.

"There is no action you need to take on your account," the email sent to customers reads. "However, please remain cautious of unexpected messages or calls claiming to be from Asos. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."

The email concluded: "We know our customers trust us with their information. We take that responsibility seriously and have already taken additional steps to further strengthen security controls."

The email to customers came after BBC News said it had been contacted by cyber criminals claiming that the breach affected customer names, addresses, phone numbers, emails and customer numbers. The notification message sent out by cyber attackers referred to cloud firm Snowflake, which stores data for many major companies. Snowflake said it has "found no compromise" of its platform after launching an investigation following the notification message.