Asos has warned shoppers to be wary of any 'unexpected' phone calls after being sent a push alert saying the fashion giant had been 'hacked'. Personal information, such as names and contact details, may have been accessed, according to both Asos and the purported hackers. But Asos, which has 16.5 million customers, told them in an email sent this morning that payment and account information was not nabbed.
Unauthorised notification explained
'We're sorry for the unauthorised notification some of you received on 6 October and any uncertainty this caused,' the email, seen by Metro, said. Asos said that initial findings from its ongoing investigation found that an 'unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials'.
'Those credentials were then used to access information on certain third-party platforms used by Asos.' Such a swindle is called a 'social engineering scam', experts say, where people gain a person's trust to get personal and financial information.
Customer advice and expert warnings
Asos said that the third party also got access to 'certain non-personal account-related information' but did not elaborate. 'There is no action you need to take on your account,' the email said. 'However, please remain cautious of unexpected messages or calls claiming to be from ASOS. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call. You can find more information and advice here.'
Experts told Metro that criminals could be masquerading as Asos to exploit customer worries about their data being exposed. Texts about resetting passwords may end with a phone call and the scammer asking to confirm the victim's card details or login. Some look-alike texts or emails might include links to websites that install shady software called malware, which steals users' personal details.
Tomas Stamulis, chief security officer at the cybersecurity software company Surfshark, says a lot of shopper data is already out there in the world from previous data breaches. 'When attackers have this combined data, they can use that knowledge to convince possible victims that they are the good guys because otherwise, how would they know so much about you?' Stamulis tells Metro.
'Good personal cybersecurity means questioning every contact you receive, and if you want to confirm whether something is legitimate, get in touch with brands yourself through official channels.' Asos said in a Q&A about the notification that it is not asking users to reset their passwords and is not sending out app notifications.