ASOS Hit by Cyberattack
Share

Many ASOS customers in the UK have reported receiving a pop-up notification on their respective mobile apps. The message was “Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
The online retailer disclosed on Tuesday that its customers were sent unauthorized notifications after a third-party system utilized for customer communication was hacked. Asos stated “We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
As per the organization, the hackers may have obtained some user data such as names and contact data. ASOS believes that payment-card information and account passwords have not been compromised. The former said that its website and app were not affected. Also, its business operations have not been impacted. The British retailer has around 17 million customers annually across more than 150 nations.
The online retailer declared “The company has cyber-security insurance with a large global provider, including business-continuity insurance. It is early to quantify any potential impact on trading.” The retailer has also posted a notification on the homepage of its website warning its customers not to engage with the rogue notification. Hackers seeking to put pressure on potential victims by intimating their customers is rare, as most extortions happen in private, so this incident may go down as a watershed moment in cyber-attack history.
SOURCES:-
https://www.securityweek.com/asos-confirms-cyberattack-data-breach/
https://www.bbc.com/news/articles/cj62ylzpr6d3o
https://theindustry.beauty/asos-confirms-cyber-attack-as-customer-data-may-have-been-accessed/
https://www.insurancebusinessmag.com/au/news/cyber/asos-confirms-cyber-cover-midbreach-as-vendor-gap-questions-mount-592700.aspx
https://www.drapersonline.com/news/asos-confirms-cyber-incident