Asos investigating after app notification warned customers of ‘hack’

Asos is investigating a suspected cyber attack after hackers hijacked the fashion retailer’s own app to claim a data breach and threaten the company.

Shares in Asos fell by as much as 11 per cent on Tuesday morning after messages sent to some customers’ phones claimed the London-based company had been “hacked” and threatened to leak unspecified material, according to screen grabs posted by multiple users on social media.

The hackers’ message read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” Snowflake is a widely used cloud-based data platform.

In a statement on Tuesday afternoon, Asos confirmed that an “unauthorised” notification had been sent to its customers and that it was working with “specialist advisers, as well as all relevant authorities” to understand the nature of the attack.

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers,” it said. “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.”

The apparent breach follows several large-scale cyber attacks on UK companies, including Jaguar Land Rover and the Co-op Group.

Shares in Asos, which is listed on London’s FTSE 250 index, closed down around 10 per cent. The stock has more than doubled in value over the past six months.

Asos said it was “too early to quantify any potential impact on trading”, noting that its website and app were operating normally, “with no current disruption to any aspects of our operations”.

Snowflake, which was not mentioned in Asos’s statement, said it was also investigating following the mobile alerts.

“At this time, we can report that we have found no compromise of the Snowflake platform,” Snowflake said. “The investigation is ongoing and we will provide further updates as soon as more information becomes available.”

Its share price was flat in morning trading in New York on Tuesday. A data breach involving Snowflake customers in 2024 was linked to several high-profile cyber attacks including AT&T, Ticketmaster and Santander.

“This is an unusually brazen and threatening message,” said Marijus Briedis, chief technology officer at NordVPN, a security provider. “What makes it even more concerning is how that threat appears to have been delivered . . . [The app notification] suggests someone has gained unauthorised access to at least part of Asos’s systems, although we don’t yet know how extensive that access is.”

Briedis warned Asos customers to watch out for phishing attacks, such as emails or texts claiming to be from Asos about passwords or payment details.

“When an attacker can potentially speak to customers through a company’s own systems, it makes the threat considerably more convincing and potentially much more damaging,” he said.

Any breach, if confirmed, would make Asos the latest in a string of UK victims of cyber attacks. Hackers recently targeted Manchester Airports Group, which in August reported that data relating to 8.7mn customers was accessed following a breach.

Last year, retailer M&S was forced to shut down its online clothing business for more than three weeks following a cyber attack that accessed some customer data.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论