International

Asos confirms hackers sent ‘unauthorised’ notification to app users

Carbonatix Pre-Player Loader

Audio By Carbonatix

Asos says it is investigating "unauthorised activity" involving third-party platforms it uses, after customers received a notification from its app that was sent by hackers.

Dozens of people told the BBC they received the strange "ASOS HACKED" message from the clothing and beauty store's app on Tuesday morning - with some saying it left them "scared" to open the app.

The notification was addressed to the company's data protection officer and IT teams in what cybersecurity experts said was a "brazen" extortion attempt.

Asos acknowledged the "unauthorised customer notification" on Tuesday afternoon, saying some "basic personal information" may have been accessed.

In an email to customers on Tuesday night, the company apologised and urged customers not to engage with the notification. It said the website and app are "operating as usual", promising customers they can "shop with confidence" while it investigates the incident.

The company has not yet informed the UK's data watchdog, the Information Commissioner's Office (ICO), about any breach.

Exactly how many ASOS customers received the notification on Tuesday remains unclear, but Google's Play Store says the ASOS app has been downloaded to Android devices more than 10 million times.

The British retailer has a substantial global footprint - serving around 17 million customers each year across more than 150 markets.

Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.

Hackers seeking to put pressure on potential victims by informing their customers is rare, as most extortion happens in private, so this incident may go down as a significant moment in cyber-attack history.

Shares in the company fell by around a tenth on Tuesday.

Charlotte Wilson, head of enterprise at cyber-security firm Check Point, called it a "deeply serious" and "brazen" attack whereby the hackers had apparently "turned Asos' own app into their ransom note".

But she told the BBC that Asos customers should not be "scared and frightened", encouraging those worried to change their passwords, avoid clicking the notification link, and be cautious about possible scam emails or texts.


Extortion message

A screenshot of a notification from the Asos app sent to an iPhone user, headlined "ASOS HACKED". It says "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it" and shares a link to a Telegram channel.
The message popped up on many Asos app users' home screens on Tuesday morning

Users of the Asos app appeared to have received the alarming notification at around 10:00 BST on Tuesday.

Headlined "ASOS HACKED" and addressed to the company's data protection officer and IT teams, it said: "We have fully compromised the Snowflake instance."

"Engage with us, or we will leak it," it added, before linking to a Telegram channel.

The message left many ASOS customers confused.

"At first I thought it was an ad or a fun promotion like 'ASOS HACKED get 50% off everything for a limited time only'," Jodie, an analyst from Edinburgh, told the BBC.

"Then I read the rest of the message which clearly showed that it wasn't an ad and instead a message to IT."

Jodie looks directly at the camera as she takes a selfie.
Jodie's concerns about what the Asos incident might mean for data she has shared with the platform, like her address, are shared by other users

"My main concern is that my information, such as bank information, home address, telephone number, has been compromised," said Erin, a student at the University of Sheffield.

She told the BBC that while her friends have expressed similar concerns about a potential data leak, her sister did not receive the notification on the Asos app.

"So the question is what is the extent? Are all customers affected even if they didn't get the notification? It's poor from Asos on all fronts."

Asos said in its statement that it took "immediate action to restrict access to the notification platforms" on Tuesday - adding it was working with specialists within and outside the company, as well as relevant authorities.

It said it does not believe payment card information or account passwords were affected, and that its site and app are "operating as normal".

"Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate," it said.

The BBC understands the National Cyber Security Centre has offered assistance to Asos.

Meanwhile, Snowflake - whose tools are used by dozens of firms to collect, analyse and store data - told the BBC its investigation was ongoing, but it had so far found "no compromise" of its platform.

The company's services have, however, been the subject of many high-profile data breaches in recent years.

Getty Images Ticketmaster's website is displayed on a MacBook screen, showing the site's search boxes where users can find events or concerns by location, date or artist.
Snowflake has previously been linked to cyber incidents targeting Ticketmaster and Santander.

According to cybersecurity expert Jen Ellis, Snowflake collects data from multiple sources for analysis, and an "enormous" firm like Asos will have lots of data about how people shop globally.

However Dan Bird, from cybersecurity firm Horizon3, said the message implied the apparent hackers' access had gone beyond the Snowflake database.

"Sending a push notification to Asos's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised," he said.

"If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door."

What can I do to protect myself?

The company has also shared a statement to the London Stock Exchange's Regulatory News Service, which provides updates to investors.

Cybersecurity experts, including Ellis, have told the BBC those behind those behind this incident are most likely trying to "apply pressure" to Asos to meet their demands, rather than target its customers.

While those who received this notification will undoubtedly be concerned, it is important to know that it does not mean your phone has been hacked.

We are still waiting to find out exactly what "basic personal information" may have been impacted in this incident, if any.

But for now, the advice is:

  • Do not click on links in the notification
  • Visit Asos's official website directly for updates
  • Watch out for emails, texts or calls offering refunds, compensation or help with your account - scammers will exploit this type of incident when they know people are worried
  • Try and use different passwords for your online services
  • Enable two-step verification on email and banking accounts
  • Keep an eye on your online transactions for anything unusual

DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:  
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.