ASOS has confirmed it was the target of a cyber attack, saying basic personal information, including customers’ names and contact details, may have been accessed.
The online fashion retailer said, however, that it does not believe payment-card information or account passwords were affected.
“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers,” ASOS said in a statement.
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
The confirmation comes after thousands of ASOS customers received a mobile app notification on Tuesday morning claiming the retailer had been hacked. The alert, titled “ASOS hacked”, directed customers to a Telegram account.
The message read: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by a Telegram link.
ASOS shares fell by more than 10% on Tuesday morning following the reports.
The retailer said its website and app are operating normally, with no current disruption to its operations.
“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate,” the statement continued.
“The company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.”
Alexander Berrai, Deputy CEO at global payments provider emerchantpay, added: “Retailers have a critical role to play in protecting their customers from fraud by embedding security into every stage of the customer journey and continually adapting defences to keep pace with emerging tactics.
“With three-quarters (75%) of consumers saying security is their top priority when shopping online, businesses that proactively invest in these measures will be best placed to build customer confidence.
“Staying ahead of the rapidly evolving fraud threat will require ongoing collaboration across the payment and retail ecosystem alongside support from policymakers and regulators.”
