Asos hackers duped employee in data breach
The hackers behind a threat to leak Asos customer data duped an employee by posing as a “trusted contact,” the fast-fashion group has said.
An unknown group shocked Asos’ millions of customers on Tuesday when they published a push notification on the online retailer’s app, claiming to have hacked into the company and threatening a data leak.
The incident triggered an immediate sell-off of the London-listed group, as its shares fell more than 13 per cent, casting doubt on the company’s ability to continue its turnaround plan.
Asos told customers on Thursday morning that it has launched a “detailed investigation” into the incident, apologising for the “uncertainty” caused by the notification. The update was the group’s first message directly to shoppers since the hack.
The fashion group said: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials.
“Those credentials were then used to access information on certain third-party platforms used by Asos.”
The company said it immediately locked down its platforms to prevent further activity and has referred the incident to “the relevant law enforcement and regulatory authorities”.
The e-commerce firm reassured its customers that the hackers did not access any payment information or passwords, though they did obtain “some personal information, including names and contact details”.
Asos said: “Once our investigation is complete, we will contact customers directly where we believe additional information, support or action may be required.
“We know our customers trust us with their information. We take that responsibility seriously and have already taken additional steps to further strengthen security controls. Thank you for your patience and for continuing to put your trust in us.”
Asos says app safe to use
Shares in FTSE-250-listed Asos ticked up following the group’s statement, gaining four per cent to 469p.
Asos users were alerted to the hack on Tuesday when a notification appeared on customers’ phones, saying: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
Snowflake is a cloud platform used to process data like clothing sizes and body measurements. It also lets users send notifications to clients’ phones.
Snowflake denied that hackers gained access to its systems. A company spokesperson said on Tuesday that it found “no compromise” of its platform.
The notification included a link to a Telegram channel, where a user named ‘Xuanye Group’ said it had obtained customer information which is “safe” on their server and “will not be touched for a designated period”.
“Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident,” they added.
British retailers have faced several cyberattacks in recent years. Last year, IT workers at Marks and Spencer were tricked by hackers who gained access to the retailer’s systems.
Asos is in the midst of a turnaround under chief executive José Antonio Ramos Calamonte. Last month, the fast fashion firm said it is on track to beat its 48-50 per cent gross margin target and its forecast of between £150m and £180m adjusted earnings.
Charles Allen, an analyst at Bloomberg Intelligence, said the hack “may temporarily cap the pace” of the company’s turnaround. “The loss of customer trust could weigh on efforts to rebuild its client base,” he said.