Asos shares drop 10% after hack alert sent to customers
Fashion retailer apologises for unauthorised push notification directing users to a Telegram account.
Online fashion retailer Asos has issued an apology to customers after an unauthorised push notification was sent to their mobile devices, falsely claiming the company had been hacked. The alert, which directed recipients to a Telegram account, has led to a fall of more than 10% in Asos's share price.
Investigation into Third-Party Platforms
The fashion giant is investigating "unauthorised activity" involving a third-party platform used for customer communication. In an email to customers on Tuesday evening, Asos urged them to disregard the notification and not to click on any external links it contained. The message received by customers stated, "Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it," followed by a Telegram link.
Asos confirmed that an "unauthorised customer notification" had been sent out through its mobile app. The company stated, "We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."
Potential Data Access
The online retailer, which has 16.5 million customers, indicated that personal information, such as names and contact details, "may have been accessed" as a result of the incident. However, the company stated it does not "believe that payment card information or account passwords, were impacted." Asos also confirmed that its website and app are operating normally with no disruption to its services.
Support from National Cyber Security Centre
The National Cyber Security Centre (NCSC), part of GCHQ, has offered Asos assistance. The notification message referenced cloud firm Snowflake, which stores data for numerous companies. Snowflake stated it has "found no compromise" of its platform after launching its own investigation. Dr Richard Horne, chief executive of the NCSC, advised individuals who received the notification not to click on suspicious links and to remain vigilant.
Asos has cyber security insurance and stated it is "too early" to quantify any potential impact on its trading. The UK is the group's largest market, accounting for 49% of revenues in the first half of the latest financial year. The incident occurs as other UK retailers have also been targeted by cyber attackers in recent years.
What Happens Next
Asos is continuing its investigation with internal and external specialists and relevant authorities. Updates will be provided if the situation changes. Customers are advised to disregard the unauthorised notification and remain vigilant against suspicious messages.
Questions this report answers
01What happened with Asos?
Asos sent an unauthorised push notification to customers falsely claiming the company had been hacked. The alert directed users to a Telegram account, prompting an investigation by Asos and a fall in its share price.
02What information may have been accessed?
Personal information such as customers' names and contact details may have been accessed. Asos has stated that it does not believe payment card information or account passwords were impacted.
03What is Asos doing about the incident?
Asos is investigating the unauthorised activity involving third-party platforms used for communication. They have restricted access to notification platforms and are working with specialist advisers and relevant authorities.
04Has the National Cyber Security Centre offered help?
Yes, the National Cyber Security Centre has offered Asos assistance as the company investigates the incident. They are also advising customers to be vigilant and not click on suspicious links.
Support is available without a police report
Find London services, specialist support and the rights set out in the Victims’ Code. If someone is in immediate danger, call 999.
Find victim supportSend a correction or case update
If a hearing, charge or outcome has changed, send the court, case number and source document so we can update the record.
Contact the desk