The fashion retailer has millions of customers. Alamy

ASOS does not believe customers payment information was accessed after 'unauthorised activity'

ASOS said said personal informational, such as names and contact details, “may have been accessed” .

LAST UPDATE | 6 Oct

ASOS HAS SAID it is investigating “unauthorised activity” involving a third-party platform after customers were sent a phone alert saying the online retailer had been hacked.

The fashion giant, which has 16.5 million customers, said personal informational, such as names and contact details, “may have been accessed” as a result.

However, the company said it does not “believe that payment card information or account passwords, were impacted”.

Customers received a mobile app notification on Tuesday, titled “ASOS HACKED”, which directed them to a Telegram account.

The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.

IMG_4237 The message as received by an Irish customer this morning. The Journal The Journal

On Tuesday afternoon, the company confirmed that an “unauthorised customer notification” had been sent out through its mobile app.

In a statement, the company said: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.

“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

“Our website and app are operating as normal, with no current disruption to any aspects of our operations.

“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”

It is understood that the National Cyber Security Centre (NCSC), a part of GCHQ, has offered ASOS assistance.

The notification message sent out by cyberattackers refers to cloud firm Snowflake, which stores data for many major companies.

Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message.

“The investigation is ongoing and we will provide further updates as soon as more information becomes available,” a spokeswoman added.

ASOS told shareholders it has cybersecurity insurance with a large provider and said it is “too early” to quantify any potential impact on its trading.

Shares in the company fell by more than 10% on Tuesday as a result.

The UK is the group’s largest market, representing 49% of all revenues in the first half of the latest financial year.

The fast fashion firm is currently undergoing a major turnaround programme in a bid to halt declining sales and return to profit.

It comes after a raft of UK retailers were targeted by cyberattackers over the past two years, including Marks & Spencer and Harrods.

With reporting by Valerie Flynn

Close
Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Submit a report
    Please help us understand how this comment violates our community guidelines.
    Thank you for the feedback
    Your feedback has been sent to our team for review.

    Leave a commentcancel

     
    JournalTv
    News in 60 seconds