Asos has said an “unauthorised party” gained access by impersonating a trusted contact to get log-in information, after customers received a phone alert saying that the retailer had been hacked.The fast fashion business told customers to “remain cautious” over unexpected messages or calls claiming to be from Asos, in an email on Thursday morning.It comes after customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account.The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link.Asos said it has undertaken a detailed investigation over the past 48 hours and found an “unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials”.It said the party then used the credentials to access information on third-party platforms used by Asos.Affected platforms were immediately locked down but Asos said the attacker gained access to some personal data, including names and contact details.The also were able to access “certain non-personal account-related information”, Asos said.Customers received a mobile app notification on Tuesday titled ‘Asos hacked’ (PA)PA MediaBut it stressed that no payment card information or account passwords were accessed.The Asos website and app were safe to use throughout the incident and “remain safe” to use, the firm said.However, the company urged customers to remain vigilant.It said: “There is no action you need to take on your account.“However, please remain cautious of unexpected messages or calls claiming to be from Asos.“We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”Asos added that it has already taken steps to strengthen its security controls and will continue with its full investigation.Read MoreThe email to customers came after BBC News said it had been contacted by cyber criminals claiming that the breach affected customer names, addresses, phone numbers, emails and customer numbers.The notification message sent out by cyber attackers referred to cloud firm Snowflake, which stores data for many major companies.Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message.
Asos says ‘unauthorised party’ impersonated contact to gain log-in details
Full Article
Original Source
Read the full article at Standard →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.