ASOS customer data may have been accessed in cyber incident
Thousands of shoppers received alarming notifications on their phones about a potential hack.
ASOS has warned customers that their personal information may have been accessed following a cyberattack involving third-party platforms used for customer communication. The online fashion retailer confirmed that customer names and contact details 'may have been accessed' as a result of the incident.
The incident came to light after thousands of ASOS customers received an alarming notification message on their phones on Wednesday morning. The message referred to a compromise of a Snowflake instance and included a link to the messaging platform Telegram. A data protection officer, or DPO, is responsible for overseeing an organisation's handling of personal data.
Investigation into unauthorised activity
In an update, ASOS stated that it does not believe payment card details or account passwords were affected by the incident. The company said it is continuing to investigate the unauthorised activity and took immediate action to restrict access to the notification platforms. ASOS is working with specialist advisers and relevant authorities.
The ASOS app and website are operating normally with no current disruption to operations, the company confirmed on Tuesday afternoon. ASOS also stated that an unauthorised customer notification had been sent out through its mobile app. Customer trust is important, and further updates will be provided if the situation changes.
NCSC offers support
The National Cyber Security Centre (NCSC), part of GCHQ, has offered ASOS assistance. Dr Richard Horne, chief executive of the NCSC, noted that cyber incidents can have repercussions for individuals beyond large businesses. He advised individuals who received the notification not to click on suspicious links and to remain vigilant to messages seeking to exploit the news of the breach.
The NCSC recommends that individuals concerned about their personal data follow advice on ncsc.gov.uk to stay safe online. The notification message referred to cloud firm Snowflake, which stores data for many companies. Snowflake stated it has found no compromise of its platform after launching its own investigation.
Market impact
ASOS informed shareholders that it has cyber security insurance. It is too early to quantify any potential impact on trading, the company said. Shares in ASOS fell by more than 10% on Tuesday following the news of the cyber incident. The UK is ASOS's largest market, representing 49% of revenues in the first half of the latest financial year.
This incident occurs after a number of UK retailers, including Marks & Spencer and Harrods, have been targeted by cyber attackers in recent years.
Questions this report answers
01What customer information may have been accessed?
ASOS has confirmed that customer names and contact details may have been accessed. The company stated that payment card details and account passwords are not believed to have been affected by the incident.
02What action has ASOS taken?
ASOS has investigated unauthorised activity, restricted access to notification platforms, and is working with specialist advisers and relevant authorities. The company's website and app are operating normally.
03What advice is being given to customers?
Customers are advised to stay vigilant and not click on any suspicious links received via messages. The National Cyber Security Centre (NCSC) recommends following advice on ncsc.gov.uk to help stay safe online.
Support is available without a police report
Find London services, specialist support and the rights set out in the Victims’ Code. If someone is in immediate danger, call 999.
Find victim supportSend a correction or case update
If a hearing, charge or outcome has changed, send the court, case number and source document so we can update the record.
Contact the desk