Asos customers receive ‘hack’ notification threatening to leak data
Push message claims fashion company’s data has been ‘fully compromised’, but website and app remain online Business live – latest updates Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. The value of Asos’s shares on the London Stock Exchange dived more than 14% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service. Continue reading...
Push message claims fashion company’s data has been ‘fully compromised’, but website and app remain online
Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data.
The value of Asos’s shares on the London Stock Exchange dived more than 14% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service.
The website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place.
The Telegram channel operated by the purported hackers, who have named themselves the “Xuanye group”, carried the message “Regarding Asos, payment information is not affected” without giving further details.
The National Cyber Security Centre, part of the government’s GCHQ intelligence agency, is offering its assistance to Asos.
The message sent out to customers said: “Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”
Snowflake is a cloud platform used to store, process and analyse data including transactions and demographic information such as clothing sizes and body measurements. It also enables push notifications to clients’ phones.
Dray Agha, the senior manager of security operations at Huntress, an online security firm, said: “Snowflake is a massive cloud database where retailers typically store sensitive customer information, it is a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the Asos mobile app also..”
The link directed Asos customers to a Telegram channel apparently operated by the Xuanye group. Cyber experts said they had not heard of the group before and the push notification might be an attempt to grab wider attention.
“It’s not unusual to see new groups emerge, and often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with ‘credibility’, ” said Aiden Sinnot, the principal threat researcher at the cybersecurity firm Sophos.
Xuanye has not been mentioned before on hacker forums or other Telegram channels. Sophos added.
Marijus Briedis, the chief technology officer at the online service provider NordVPN, said: “What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”
The potential hack comes after a string of British retailers including Marks & Spencer , the Co-op and Harrods suffered cyber incidents last year. M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean.