Asos hacked: Cyber attack was worse than thought and customers’ personal information is at risk, retailer says | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Asos customers’ personal information was stolen during a major hack on the online clothes retailer, it has said.

On Tuesday, Asos customers received an alert on their phone that read “ASOS HACKED” and claimed that cyber attackers had broken into its systems. The message appeared to threaten Asos with the release of customer data.

Hours after the hack, Asos finally confirmed that it had been hit by a cyber attack, but said that it was still investigating the full scale of what had happened. Now, it has told customers that an “unauthorised party” had impersonated a “trusted contact” to get a log-in, and had used that to steal their personal information.

The fast fashion business told customers to “remain cautious” about unexpected messages or calls claiming to be from Asos, in an email on Thursday morning.

It comes after customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account.

Asos said it has undertaken a detailed investigation over the past 48 hours and found an “unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials”.

It said the party then used the credentials to access information on third-party platforms used by Asos.

Affected platforms were immediately locked down but Asos said the attacker gained access to some personal data, including names and contact details.

Bitdefender logo

The ideal summer spot? Away from scams.

Get All-in-One Protection for Your Digital Life

LEARN MORE

ADVERTISEMENT

Bitdefender logo

The ideal summer spot? Away from scams.

Get All-in-One Protection for Your Digital Life

LEARN MORE

ADVERTISEMENT

They were also able to access “certain non-personal account-related information”, Asos said. It did not say what that information was, but the BBC reported that hackers had shown evidence that they had data on what users had searched on the site.

But it stressed that no payment card information or account passwords were accessed.

“While passwords and payment information appear to be safe, the data that has been stolen will be incredibly valuable to scammers and used for many years to come,” said Jake Moore, global cybersecurity adviser at ESET. “Knowing someone’s name, contact details and in this case, their shopping habits, gives cybercriminals the opportunity to create very convincing and personalised scams.

“We often focus on financial information being stolen but personal data can be just as powerful in the wrong hands, especially when it seems believable and not at all threatening at first sight. This is a timely reminder that, where possible, it’s best not to store data in online shopping accounts and instead favour signing in as a guest where possible.”



Click Here For The Original Source.

——————————————————–

..........

.

.