Asos says hacker accessed customer data after impersonating trusted contact
Asos says a hacker impersonated a trusted contact to access customer names and contact details; shares fell about 10% after a push alert.
The disclosure followed what Asos described as a “detailed, 48-hour investigation.” The retailer said an unidentified third party had accessed basic personal information of customers, including names and contact details. It said the group also accessed “certain non-personal account related information,” without clarifying what that information was. Payment card details and passwords were not accessed, Asos added.
The Guardian reported that thousands of users of the Asos app received the notification on Tuesday, which included a link to the Telegram messaging service. The push alert and the apparent breach sent Asos shares diving by about 10 percent.
In a message to customers on Thursday, Asos said: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to access information on certain third-party platforms used by Asos.” The company said affected platforms were immediately locked down to prevent further access, and that a full investigation was launched with internal and external cyber experts. Asos said it was also working with relevant law enforcement and regulatory authorities.
Asos said its website and app remained safe to use and that customers did not need to take action. It said it had “already taken additional steps to further strengthen security controls.” The company warned customers to remain cautious of unexpected messages or calls claiming to be from Asos, saying it would never ask them to share passwords, security codes or payment details through an unsolicited message or call.
Asos pledged to contact customers directly once its investigation was complete and “where we believe additional information, support or action may be required.” The Telegram channel operated by the purported hackers, who have named themselves the Xuanye Group, carried a message assuring Asos customers that “payment information is not affected,” according to The Guardian. Cyber experts said they had not heard of the group before and that the push notification could be an attempt to gain wider attention.
Editor's Summary
Asos said a hacker impersonated a trusted contact to access an employee account and customer names and contact details, though payment card details and passwords were not affected. The incident followed a push notification to app users and a roughly 10 percent fall in Asos shares, and the company said it is working with cyber experts and authorities. A Telegram channel linked to a previously unknown group, Xuanye Group, said payment information was not affected.