in

Asos warns customer data may be compromised after ‘unauthorised’ app access

Asos is investigating unauthorised access to its app system after shoppers received a notification claiming hackers had “fully compromised” its data.

The online fashion retailer said basic personal information including name and contact details might have been accessed by an unidentified third party but it did not believe payment card records or passwords had been compromised.

It said in a statement: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

“Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”

It later apologised directly to customers, saying: “We’re sorry that you may have received an unauthorised push notification from us earlier today. Please disregard the notification and do not click or engage with the external third-party link it contained.”

The value of Asos’s shares on the London Stock Exchange dived more than 14% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service.

Shares closed down by 9.56% after Asos announced it had cybersecurity insurance with a large global provider, including business continuity insurance. However, the company added: “It is too early to quantify any potential impact on trading.”

The message sent out to customers said: “Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”

Snowflake is a cloud platform used to store, process and analyse data including transactions and demographic information such as clothing sizes and body measurements. It also enables push notifications to phones.

The Telegram channel operated by the purported hackers, who have named themselves the Xuanye Group, carried a message assuring Asos customers that “payment information is not affected” and a further post stating “the app is safe to use”.

Indicating that Asos had been set some form of deadline, the post added: “The incident involves customer information, it is safe on our server, and it will not be touched for a designated period.”

The National Cyber Security Centre (NCSC), part of the government’s GCHQ intelligence agency, is offering assistance to Asos.

The NCSC chief executive, Dr Richard Horne, said: “The unauthorised notification sent out to Asos customers has brought into the light how cyber incidents do not simply affect big business but can have repercussions for individuals much more widely too.”

Dray Agha, the senior manager of security operations at Huntress, an online security firm, said: “Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.”

The link directed Asos customers to a Telegram channel apparently operated by the Xuanye Group. Cyber experts said they had not heard of the group before and the push notification could be an attempt to grab wider attention.

“It’s not unusual to see new groups emerge, and often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with ‘credibility’,” said Aiden Sinnott, the principal threat researcher at the cybersecurity firm Sophos.

Xuanye had not been mentioned before on hacker forums or other Telegram channels, Sophos added.

Marijus Briedis, the chief technology officer at the online service provider NordVPN, said: “High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”

The potential hack comes after a string of British retailers, including Marks & Spencer, the Co-op and Harrods, suffered cyber incidents last year. M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean.