‘ASOS Hacked’ Warns Notification Sent To Customers
Customers of the British fashion retailer ASOS are being sent notifications claiming the company has been hacked.
Shoppers in several countries have reportedly received the notifications, which appear to come from a hacking group attempting to extort money from the firm.
The notification has the header “ASOS HACKED” before adding: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The notification also contains a web link, although it would be deeply unwise to click on that URL.
The fact the attackers have seemingly managed to gain access to ASOS’s app notification system is “concerning”, according to NordVPN’s chief technology officer, Marijus Briedis. “A message apparently written for ASOS’s data protection and IT teams has instead been pushed directly to customers through the company’s own app notification system,” he said. “That suggests someone has gained unauthorized access to at least part of ASOS’s systems, although we don’t yet know how extensive that access is.”
Snowflake is a data storage company that many retailers use for collecting user data. Snowflake has been linked to cybersecurity attacks in the past, with companies including Ticketmaster, AT&T and Advanced Auto Parts targeted after breaches of Snowflake’s systems.
ASOS has yet to comment publicly on the alleged attack, although the BBC report that customers reporting the incident to the company’s chatbot are being told that the company is “aware of the notification and are currently investigating.” The ASOS website is currently operating as normal with no warnings to customers posted at the time of writing.
Security experts say it’s imperative that ASOS communicates quickly with its customers. “For customers, the biggest question right now is my data safe?,” said Ragu Nandakumara, VP of industry strategy at breach containment specialists Illumio. "ASOS must quickly confirm whether data has in fact been taken and, if so, who is affected and what exactly has been compromised. "If confirmed, this incident show how difficult it has become for retailers to secure increasingly interconnected digital ecosystems. Modern retail is built on an ecosystem of cloud platforms, applications and third-party providers, and every trusted connection can potentially become a route an attacker tries to exploit.”
Jake Moore, global cybersecurity advisor for security firm ESET has described the alleged attack as “one of the most visible hacks in history” on his X feed . Ironically, ASOS stands for “as seen on screen."
ASOS has been approached for comment.
ASOS’s share price has tumbled by about 12% at the time of writing, as news of the alleged hack began to spread over social media. The BBC is reporting that the U.K.’s National Cyber Security Centre (NCSC) has offered assistance to ASOS.
If the company has been hacked, it will be the latest in a series of big-name retailer casualties in the U.K. Last year, M&S was the victim of a hack attack that took down the company’s online store for months and severely harmed its profitability. The Co-Op and Harrod’s were also exposed to similar attacks.
ASOS has online stores in several countries around the world, including the U.S., France, Germany and Spain.