Yesterday morning, people received a very odd push notification from the Asos app, to say the least.
‘Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,’ the message read.
The notification was addressed to the fashion giant’s data protection officer and IT teams in a message experts told Metro was a ransom note.
The pop-up asked users to jump through a few Telegram hoops and join a page, where the hackers said they had obtained ‘customer information’.
Asos confirmed that this was an ‘unauthorised customer notification’ and that shopper names and contact details may have been accessed
I shop at Asos – what should I be doing?

Not much, according to Asos.
The e-commerce giant has said it’s safe to browse on its app and it has restricted access to its notification platforms while it investigates.
A Q&A on the Asos website says: ‘We are not currently asking customers to change their Asos account password or take any other action.
‘If this changes, we will contact affected customers directly.’
This doesn’t mean shoppers should do nothing, though, says Tomas Stamulis, chief security officer at the digital privacy tool Surfshark.
The hackers and Asos both said that payment card records or passwords were not compromised.

But the breach may open the door for other criminals to try and get their hands on these details, Stamulis says.
Crooks may try their luck with a phishing scam. This involves posing as Asos to frighten people into clicking dodgy links in emails to reset their password or texts saying their order has been delayed.
‘There is usually an increase in volume following an attack on a company like Asos because attackers know customers may be worried about their data being exposed,’ Stamulis says.
‘If you’ve clicked a suspicious notification or link, don’t assume the worst, but act quickly.
‘Close the page straight away and avoid entering any personal information, passwords or payment details.’
I clicked a dodgy link from ‘Asos’, what should I do?

Usually, one of two things happens. Sometimes, it’ll just load a blank webpage – but not everything is as it seems.
It’s probably activated malware, shady software that silently steals your personal information.
‘If anything has downloaded or been installed, disconnect the device from the internet and run a full malware scan,’ Stamulis adds.
Or the link will bring you to a slick-looking webpage that spoofs Asos, asking the user for their password or other info.
If you do, there’s no shame in that, Stamulis says. You’ll need to change that password from a ‘clean device’, including your email log-in.
‘Access to your inbox can give criminals a route into other services through password resets,’ Stamulis says.

‘Use a unique password for each account and enable two-factor authentication where possible.’
Two-factor authentication helps keep scammers and hackers out of your accounts by making the log-in process a two-part process.
You’ll need to set up a password as well as another ‘factor’, hence the name, like being emailed or texted a code, or using an authenticator app.
Some services let people use a passkey that’s stored on your phone or computer, locked behind a pin or biometric authorisation (such as a fingerprint or facial recognition).
Speaking of emails, keep an eye out for any ones about unfamiliar logins, password changes or transactions over the coming days and weeks.
‘Be particularly vigilant about unexpected calls, texts or emails offering to help with the issue, as scammers can use the situation to pose as a trusted company or support service and try to gather more information from you,’ adds Stamulis.

Aimee Speight, a communications expert and founder of Highland Consulting, says this is the kind of advice Asos should be giving.
‘Asos confirmed names and contact details may have been accessed, which is a scammer’s starter pack, yet there isn’t a single line telling customers what to look out for,’ she says.
‘The most useful thing Asos can do is push a notification of its own: here’s what happened, here’s what to watch for, and we will never ask for your details by link.’
Asos shares tumbled by 14% on the London Stock Exchange after the bizarre notification was broadcast.
Marty Bauer, e-commerce expert at the marketing software firm Omnisend, says the incident may have damaged the ‘trust’ shoppers had in Asos.
‘With Black Friday approaching, Asos will want existing customers to feel comfortable buying again,’ Bauer says.
‘If shoppers disengage from push notifications and email now, that is revenue the brand may find difficult to win back.’
Get in touch with our news team by emailing us at webnews@metro.co.uk.
For more stories like this, check our news page.
MORE: The best supermarket fashion buys under £60 from M&S, Tesco, Asda and Sainsbury’s
MORE: This simple switch can ease back pain — as long as you’re prepared to feel like a ‘loser’
MORE: Barrel-leg jeans, Harrington jackets and chunky knits dominate Topman’s new collection
Click Here For The Original Source.
