ASOS confirms personal details were accessed in hack update as retailer issues apology

ASOS has confirmed that personal details were accessed after an “unauthorised notification” was sent out to users in a new update on the “hacking” incident.
The message, which contained a link to a Telegram chat, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

Screengrab of the mobile phone message of sent to customers of online clothing retailer ASOS claiming that the company has been hacked
PA
The company later said it had found “no compromise” of its platform and urged customers to ignore the notification and not click on links in the message.
The online retailer said personal information, such as names and contact details, “may have been accessed”, but said it did not believe that payment card information or account passwords were impacted.
In an update sent to its 16.5 million customers on Thursday, ASOS apologised for the incident “any uncertainty this caused”.
It explained that in the past 48 hours, an investigation into the incident has been underway.
“We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials. Those credentials were then used to access information on certain third-party platforms used by ASOS.
“The affected platforms were immediately locked down, ensuring that no further information could be accessed and a full investigation was launched with the support of both internal and external cyber experts. We are also working with the relevant law enforcement and regulatory authorities.”
The ASOS app as seen on an iPhone
AFP/Getty
It confirmed that the unauthorised party gained “access to some personal information, including names and contact details, and certain non-personal account related information”.
However, it confirmed that no payment card information or account passwords were accessed.
It added that the website and app were safe to use throughout, and continue to remain safe to use today
“There is no action you need to take on your account,” it stressed. “However, please remain cautious of unexpected messages or calls claiming to be from ASOS. We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
The investigation remains ongoing and the retailer said it will contact customers directly if additional action is required.
Shares in ASOS fell more than 10% on Tuesday after the notification was sent.
It interrupted a strong run for the online fashion retailer, whose shares had nearly doubled over the past year.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.