Asos Hackers Claim Access to Detailed Customer Profiles
Fashion retailer confirms unauthorized access to customer data after hackers threaten to leak information.
Hackers who infiltrated the fashion retailer Asos's website are believed to have accessed detailed profiles of potentially millions of customers, going beyond the basic contact information initially feared.
The breach came to light after customers received an "unusually brazen" message threatening to leak their data. This message claimed the hackers had "fully compromised the Snow flake instance," referring to the cloud-based data platform used by Asos. The hackers, who identified themselves as the "Xuanye Group" on a newly created Telegram channel, demanded a ransom payment from Asos in exchange for deleting the customer information.
Cyber-criminals could now possess shoppers' names, addresses, phone numbers, email addresses, and records of past searches on the site. Asos has cautioned customers to be vigilant about unexpected messages or calls claiming to be from the company, stating they will never request passwords, security codes, or payment details through unsolicited communication.
Asos confirmed on Tuesday that "basic personal information" may have been accessed, but stated that it does not believe payment card details or passwords were impacted. The company has since sent an email to consumers and issued statements to the London Stock Exchange regarding the unauthorized activity, which it is investigating with specialist advisers and relevant authorities.
Cyber-security experts described the hackers' notification as "psychological warfare designed to whip up panic." Marie Wilcox, VP of market strategy at cyber-security firm Binalyze, noted that such tactics aim to pressure the targeted company into paying a ransom rather than developing a rational response.
Snowflake, the platform involved, stated that it has found no compromise of its platform. The company, which has 17 million customers in 150 countries, saw its shares fall by more than 9% following reports of the hacking. Asos is currently undergoing a turnaround program to address declining sales and return to profitability.
Under UK data protection law, Asos is legally obligated to inform customers if their data has been breached. Consumer watchdog Which? emphasized the importance of timely notification and clear explanations of consequences and protective steps for affected customers.
This incident follows a series of cyber attacks in the UK, including recent breaches affecting charities through the Beacon CRM system and a prior attack on M&S and Co-op.