Asos said it was working with legal and regulatory authorities, and the Asos website and app were safe to use.
Customers are told payment details and passwords were not compromised when employee account was breached Business live – live updates Hackers gained access to Asos customer names and contact details by impersonating a “trusted contact” to gain access to one of its employee’s accounts, the retailer has said.
Thousands of users of the online fashion seller’s app received a notification on Tuesday titled “Asos hacked” with a link to the Telegram messaging service, sending its shares diving by about 10%.
After carrying out a “detailed, 48-hour investigation” into the incident Asos confirmed that basic personal information of customers, including names and contact details, had been accessed by an unidentified third party.
Asos said the group had also gained access to “certain non-personal account related information”, without clarifying what this was.
Payment card details or passwords had not been accessed, it added.
The retailer said in a message to customers on Thursday: “We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain login credentials.
Those credentials were then used to access information on certain third-party platforms used by Asos.
“The affected platforms were immediately locked down, ensuring that no further information could be accessed, and a full investigation was launched with the support of both internal and external cyber experts.
We are also working with the relevant law enforcement and regulatory authorities.” It said the Asos website and app continued to be safe to use and customers did not need to take action and added that it had “already taken additional steps to further strengthen security controls”.
However, the company warned: “Please remain cautious of unexpected messages or calls claiming to be from Asos.
We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.” Asos pledged to contact customers directly once its investigation was complete and “where we believe additional information, support or action may be required”. skip past newsletter promotion after newsletter promotion The Telegram channel operated by the purported hackers, who have named themselves the Xuanye Group, that users were directed to on Tuesday carried a message assuring Asos customers that “payment information is not affected”.
Cyber experts said that they had not heard of the group before and that the push notification could be an attempt to gain wider attention.
Explore more on these topicsAsos Retail industry Hacking Cybercrime Telegram Online shopping news Share Reuse this content