Asos hackers ‘in possession of detailed profiles of potentially millions of customers’


Hackers who infiltrated fashion firm Asos’s website are feared to have detailed profiles from millions of customers.

The incident saw Asos customers receive an ‘unusually brazen’ message on their phones claiming to be from hackers threatening to leak their data. 

In the aftermath, the retailer confirmed the ‘basic contact details’ of users had been taken in the online security breach but said it did not believe ‘payment card details or passwords were impacted’. 

Asos said an ‘unauthorised party’ gained access by impersonating a trusted contact to get log-in information. 

The company added that it has already taken steps to strengthen its security controls and will continue with its investigation. 

But it is now believed the cyber-criminals behind the attack could have access to more information than Asos originally confirmed. 

Shoppers’ names, addresses, phone numbers, email addresses and past searches on the site could all have been breached, with the BBC saying it had been contacted by hackers who claimed they had access to extra information about Asos customers.

In a new email to consumers, Asos said: ‘Please remain cautious of unexpected messages or calls claiming to be from Asos.

Millions of customers are feared to be affected by a cyber-hack of the fashion firm Asos

‘We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.’

The Asos website and app were safe to use throughout the incident and ‘remain safe’ to use, the firm said today, though the company urged customers to remain vigilant.

Messages sent by the hackers to customers’ phones said they had ‘fully compromised the Snowflake instance’, referring to the online platform that collects data, including that of customers. 

The notification included a threatening message to Asos: ‘Engage with us or we will leak it’.

It also contained a link to the hackers’ Telegram channel, the ‘Xuanye Group’, that was only created the previous day.

It is understood messages later appeared on that channel claiming that ‘customer information is safe on our server’ and ‘it will not be touched for a designated period’.

One message from the hackers is said to read: ‘Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident.’

The hackers had demanded a ransom payment from Asos in exchange for deleting customer information.

It quoted a text from messaging app Telegram, saying: ‘Our message is clear, and simple to recognise. The organisation must contact us or we will leak it [customers’ data], that is what we said.

‘The two-week period is intended for them to make contact, they know what happened.’

The hackers said in an online notification: ‘Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.’

Snowflake is a cloud-based platform that firms use to store, process and analyse data and an ‘instance’ refers to a customer’s individual environment on the platform.

Shares in Asos, which also owns brands including Topshop and Miss Selfridge, fell by more than 9 per cent after reports of the hacking emerged.

Cyber-security experts said the hackers’ ‘unusually brazen’ notification was ‘designed to whip up panic’.

A statement was released by Asos on Tuesday in which the firm apologised to customers if they had received the ‘unauthorised push notification’. 

In a further statement to the London Stock Exchange, it said: ‘Asos can confirm that, at around 10am today, an unauthorised customer notification was sent to Asos customers.’ 

‘We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.

‘We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

‘Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.

‘Our website and app are operating as normal, with no current disruption to any aspects of our operations.

‘Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.

‘The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.’

Katherine James, director of Snowflake’s Europe, Middle East and Africa communications team, told the BBC: ‘As soon as we became aware of the notification that is currently being reported, we began an investigation.

‘At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously.

‘The investigation is ongoing and we will provide further updates as soon as more information becomes available.’

Asos says it has 17 million customers in 150 countries.

Panicked customers reacted online to the ‘crazy notification’ and some said they had ‘never deleted my payment methods so quick’.

Marie Wilcox, VP of market strategy at cyber-security firm Binalyze, said: ‘This notification was psychological warfare, designed to whip up panic. Attackers know that any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response.’

Asos is legally obliged to tell customers if their data has been breached under the UK’s data protection law.

Kat Cereda, from consumer watchdog Which?, told the BBC this should be done ‘without any undue delay’ and the firm should ‘explain the consequences and outline what steps they are going to be taking to protect you’. 

Britain is Asos’s largest market, representing 49 per cent of all revenues in the first half of the latest financial year.

The fast-fashion firm is undergoing a major turnaround programme to halt declining sales and return to profit.

Mike Ashley’s Frasers Group owns 29.26 per cent of Asos and is the firm’s largest shareholder. 

Britain has been hit by several cyber attacks in recent months. In August, up to 1,000 charities, including Breast Cancer UK, English National Ballet and the Molly Rose Foundation, were targeted. 

Criminals targeted Beacon CRM, which provides customer management software to the charity sector.

It is thought the firm mistakenly published an access key online that allowed hackers to copy its databases.

Meanwhile, M&S and Co-op were targeted by a cyber-attack in the spring and summer of last year. 

Notorious hacker group Scattered Spider was linked to the hack that left shelves empty for weeks and forced M&S to stop accepting all online orders and payments.



Source link

Her Solo Reinvention and the Vulnerability Behind Coachella

Ted Lasso’s Brendan Hunt Addresses Potential Season 5 

Leave a Reply

Your email address will not be published. Required fields are marked *