Asos says customer data may have been accessed after ‘unauthorised activity’
Asos has said it is investigating “unauthorised activity” involving a third-party platform after customers were sent a phone alert saying the online retailer had been hacked.
The fashion giant, which has 16.5 million customers, said personal informational, such as names and contact details, “may have been accessed” as a result.
However, the company said it does not “believe that payment card information or account passwords, were impacted”.
Customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account.
The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.
On Tuesday afternoon, the company confirmed that an “unauthorised customer notification” had been sent out through its mobile app.
In a statement, the company said: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.
“Our website and app are operating as normal, with no current disruption to any aspects of our operations.
“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”
It is understood that the National Cyber Security Centre (NCSC), a part of GCHQ, has offered Asos assistance.
The retailer told shareholders it has cyber security insurance with a large provider and said it is “too early” to quantify any potential impact on its trading.
Shares in the company fell by more than 10% on Tuesday as a result.
Published: by Radio NewsHub