ASOS Probes Hack After Push Notifications to Customers
ASOS says names and contact information may have been accessed, but it does not believe payment details or passwords were compromised.
ASOS says it is investigating an extortion attack in which attackers sent push notifications to its customers claiming the company's Snowflake cloud instance had been compromised, according to The Guardian.
The notifications addressed the company's data protection officer and IT personnel and said the attackers had fully compromised the Snowflake instance. The message linked to a Telegram channel claiming to be run by Xuanye Group.
ASOS said it is investigating unauthorised activity involving third-party platforms used to communicate with customers. The retailer restricted access to the notification platforms and is working with internal and external advisers and relevant authorities.
The company said customer names and contact information may have been accessed, but it does not believe payment details or passwords were compromised. ASOS added that its app and website were operating as usual.
Quick answers
Was ASOS hacked?
ASOS said it is investigating unauthorised activity involving third-party platforms used to communicate with customers, after attackers sent push notifications claiming its Snowflake cloud instance had been compromised.
What ASOS customer data may have been accessed?
ASOS said customer names and contact information may have been accessed, but it does not believe payment details or passwords were compromised.
Is the ASOS app and website still working?
ASOS said its app and website were operating as usual.