Asos customers receive ‘hack’ notification threatening leak

Asos customers receive ‘hack’ notification threatening leak

Asos said it was aware of the reports of a hack but did not confirm or comment further. Photograph: Justin Tallis/AFP/Getty ImagesView image in fullscreenAsos said it was aware of the reports of a hack but did not confirm or comment further. Photograph: Justin Tallis/AFP/Getty ImagesAsos customers receive ‘hack’ notification threatening leakPush message claims fashion company’s data has been ‘fully compromised’, but website and app remain online

Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data.

The value of Asos’s shares on the London Stock Exchange dived almost 12%, after thousands of customers received a mobile app notification titled “Asos hacked” with a link which sent them to the Telegram messaging service.

However, the website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place.

The message sent out to customers said: “Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”

View image in fullscreenAn Asos app notification claiming the retailer has been hacked. Photograph: ScreengrabSnowflake is a cloud platform used to store, process and analyse data collected by Simon AI including transactions and demographic information, such as clothing sizes and body measurements. It also enables push notifications to clients’ phones.

Dray Agha, the senior manager of security operations at Huntress, an online security firm, said: “Snowflake is a massive cloud database where retailers typically store sensitive customer information – it is a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the Asos mobile app also. This is clear public extortion.

“Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.”

Marijus Briedis, the chief technology officer at the online service provider NordVPN said: “What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”

The potential hack comes after a string of British retailers including Marks & Spencer, the Co-op and Harrods suffered cyber incidents last year. M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean.

📰 Original Source Attribution

Reported by theguardian.com.

Read Original Report at theguardian.com ↗
Share: WhatsApp WhatsApp
💬

Comments (0)

Join the Conversation

No comments yet. Be the first to share your opinion!

You may like