Want to bookmark your favourite articles and stories to read or reference later? Start your Independent Membership today.
Already a member?
Log in
Asos customers’ personal information was stolen during a major hack on the online clothes retailer, it has said.
On Tuesday, Asos customers received an alert on their phone that read “ASOS HACKED” and claimed that cyber attackers had broken into its systems. The message appeared to threaten Asos with the release of customer data.
Hours after the hack, Asos finally confirmed that it had been hit by a cyber attack, but said that it was still investigating the full scale of what had happened. Now, it has told customers that an “unauthorised party” had impersonated a “trusted contact” to get a log-in, and had used that to steal their personal information.
The fast fashion business told customers to “remain cautious” about unexpected messages or calls claiming to be from Asos, in an email on Thursday morning.
It comes after customers received a mobile app notification on Tuesday, titled “Asos hacked”, which directed them to a Telegram account.
Asos said it has undertaken a detailed investigation over the past 48 hours and found an “unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials”.
It said the party then used the credentials to access information on third-party platforms used by Asos.
Affected platforms were immediately locked down but Asos said the attacker gained access to some personal data, including names and contact details.
ADVERTISEMENT
ADVERTISEMENT
They were also able to access “certain non-personal account-related information”, Asos said. It did not say what that information was, but the BBC reported that hackers had shown evidence that they had data on what users had searched on the site.
But it stressed that no payment card information or account passwords were accessed.
“While passwords and payment information appear to be safe, the data that has been stolen will be incredibly valuable to scammers and used for many years to come,” said Jake Moore, global cybersecurity adviser at ESET. “Knowing someone’s name, contact details and in this case, their shopping habits, gives cybercriminals the opportunity to create very convincing and personalised scams.
“We often focus on financial information being stolen but personal data can be just as powerful in the wrong hands, especially when it seems believable and not at all threatening at first sight. This is a timely reminder that, where possible, it’s best not to store data in online shopping accounts and instead favour signing in as a guest where possible.”
Click Here For The Original Source.

