How can I protect my data after the ASOS hack and who was affected?
Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in
Want to bookmark your favourite articles and stories to read or reference later? Start your Independent Membership today.
Fashion giant ASOS is investigating āunauthorised activityā involving a third-party platform after customers were sent a phone alert saying the online retailer had been hacked.
Personal information, such as names and contact details, may have been accessed in the hack, according to the company.
But the retailer, which has 16.5 million customers, said it does not ābelieve that payment card information or account passwords were impactedā.
Some customers received a strange looking message from the retailer, leaving many concerned their personal details are at risk.
Here is what happened and what to do next.
Some ASOS customers received an unauthorised push notification from ASOS on Tuesday October 6.
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” the message read.
The message was followed by a Telegram link.
ASOS has emailed its customers apologising for the āunauthorised push notification” and urged customers not to click on the external link and to disregard the message.
The notification message sent out by cyber attackers refers to cloud firm Snowflake, which stores data for many major companies.
Snowflake said it has āfound no compromiseā of its platform after launching an investigation following the notification message.
āThe investigation is ongoing and we will provide further updates as soon as more information becomes available,ā a spokeswoman added.
The National Cyber Security Centre (NCSC), a part of GCHQ, has offered ASOS assistance.
All ASOS customers should assume they are affected by this incident, even those who did not receive the push notification, NCSC said.
But receiving a push notification doesnāt mean your phone has definitely been hacked.
The incident is being investigated, but in the meantime the advice is:
Donāt click any suspicious links: NCSC has urged customers to look out for suspicious messages, which may arrive some time after the breach incident. Cyber security experts and ASOS have also urged customers to not click on the Telegram link included on the push notification.
Change passwords and security: Experts suggest updating passwords on your ASOS account as well as any accounts that share the same password. āUsing passkeys, or strong, separate passwords plus two-step verification for your accounts will keep you secure even if your data is breached,ā according to NCSC.
Check online transactions: Although ASOS has said customer payment details and account passwords have not been affected. Cyber security experts suggest keeping an eye on any online transactions, especially if they look unusual.
Following the data breach criminals may capitalise on the breach’s publicity with more phishing scams, Zain Javed, director of strategic growth and cyber services at Citation Cyber has warned.
āCustomers should be particularly suspicious of emails or text messages saying things such as āyour ASOS account has been compromisedā, āverify your accountā, āreset your passwordā, āconfirm your payment detailsā or āclaim compensation for the ASOS breachā,ā he said.
āWe could also see fake delivery notifications, refund messages or discount vouchers designed to look as though they have come from ASOS. This is particularly effective after a genuine cyber incident because the criminal doesn’t have to invent the story. Customers already know something has happened, so a message saying ‘we’re contacting you following yesterday’s security incident’ immediately feels more believable.
āAnyone receiving a message like that should avoid the link and instead open the ASOS app or type the ASOS website address directly into their browser. ASOS itself advises customers that it will never ask for passwords or sensitive card information through social media and warns against unfamiliar links.ā
Join thought-provoking conversations, follow other Independent readers and see their replies
Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in
Reported by independent.co.uk.
Read Original Report at independent.co.uk ā
Comments (0)
No comments yet. Be the first to share your opinion!