ASOS issues statement and explains how millions of customers got ‘hack’ message | #hacker


ASOS has issued a new statement and explained exactly how millions of customers received an eerie ‘hack’ message earlier this week.

A message appeared on the screens of users of the mobile application which read ‘ASOS HACKED’ on Tuesday morning (6 October).

It then appeared to go on to threaten the owners of the app over a possible ‘leak’ but left users bewildered about what it meant.

The alert raised security concerns about the app and site being hacked and what that meant for shoppers and their data.

The message went on to read: “Dear ASOS DPO and IT, we have fully compromised the snowflake instance. Engage with us or we will leak it.”

The alert had been sent out via a push notification which was delivered to phone users that have the app downloaded, sparking concern on social media.

The ASOS message that appeared (LADbible)

Now, the online fashion brand has responded, claiming that hackers had gained access through an employee account.

“We’re sorry for the unauthorised notification some of you received on 6 October and any uncertainty this caused,” an update read.

“Our priority will always be to protect our customers, to understand exactly what happened and to share accurate information as quickly as possible.

“Our teams, supported by external experts, have undertaken a detailed investigation over the last 48 hours.

“While the full investigation will continue over the coming weeks, we wanted to provide you with an update.”

ASOS users received the notification (Nathan Stirk/Getty Images)

ASOS users received the notification (Nathan Stirk/Getty Images)

Platforms were ‘locked down’

It continued: “We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials.

“Those credentials were then used to access information on certain third-party platforms used by ASOS.

“The affected platforms were immediately locked down, ensuring that no further information could be accessed and a full investigation was launched with the support of both internal and external cyber experts.

“We are also working with the relevant law enforcement and regulatory authorities.”

However some personal information including names and personal information was also seized – but not bank account details.

“Our investigation found that the unauthorised party had access to some personal information, including names and contact details, and certain non-personal account related information.

“Since we began our internal investigation on 6 October, we have found that no payment card information was accessed, no account passwords were accessed and the ASOS website and app were safe to use throughout, and remain safe to use today.

“There is no action you need to take on your account. However, please remain cautious of unexpected messages or calls claiming to be from ASOS.”



Click Here For The Original Source.

——————————————————–

..........

.

.