Asos is investigating after a push notification despatched from its cell app to clients immediately claimed that hackers had “absolutely compromised” a knowledge platform utilized by the net style retailer and threatened to leak what they’d obtained.
The alert learn: “Expensive ASOS DPO and IT, now we have absolutely compromised the Snowflake occasion. Have interaction with us, or we are going to leak it.” DPO refers to knowledge safety officer, and Snowflake seems to be a reference to the US cloud-based knowledge platform of that identify.
Asos stated it was nonetheless investigating and had but to find out the reason for the alert. No cyberattack has been confirmed. The corporate’s web site and app each remained accessible afterwards.
Shares within the FTSE 250 group fell by as a lot as 14 per cent to 432p.
The notification linked to a Telegram channel referred to as the Xuanye Gateway, which is new and doesn’t match any recognized hacking group. The group has claimed that cost data just isn’t affected.
Marijus Briedis, chief know-how officer at NordVPN, stated: “That is an unusually brazen and threatening message. The attackers aren’t merely claiming to have breached ASOS, they’re publicly telling the corporate to interact with them or they are going to leak what they are saying they’ve obtained.”
He added: “If that declare proves real, the crucial query can be what data was held there and whether or not any of it was accessed or downloaded. At this stage, nonetheless, clients shouldn’t assume their private or cost data has been stolen, that hasn’t been established.”
Alan Woodward, a professor of cybersecurity at Surrey College, stated the hackers “have in all probability … received entry to the database, which implies, if I used to be an Asos buyer, I’d assume that any individual’s received my private knowledge.”
Woodward additionally stated that if the attacker had solely compromised the advertising or push notification system, the alert might be an try and pressure Asos to pay a ransom shortly. “The hackers know {that a} public message seen by tens of millions of shoppers will severely injury the model’s status and inventory value instantly, whether or not the information leak declare is true or not,” he stated.
Charlotte Wilson, head of enterprise for the UK & Eire on the cybersecurity firm Test Level, stated individuals ought to be “extraordinarily suspicious of emails, texts or messages claiming their Asos account has been compromised, providing refunds or asking them to reset passwords by a hyperlink”.
The Nationwide Cyber Safety Centre’s steerage on knowledge breaches tells clients to contact an affected organisation by its official web site or social media channels, and to not use the hyperlinks or contact particulars in any messages they’ve been despatched.
Snowflake was the topic of a hacking marketing campaign in 2024, when clients together with Ticketmaster and Santander had knowledge stolen. Hackers from the ShinyHunters group stole usernames and passwords the businesses used to entry the service, and Snowflake afterwards launched multi-factor authentication on all its accounts.
If confirmed, the incident would observe the assaults on Marks & Spencer and the Co-op in spring final yr, and the assault on Jaguar Land Rover, which the Cyber Monitoring Centre estimated induced a £1.9bn impression.
The alert comes as Asos pursues a turnaround plan underneath chief government José Antonio Ramos Calamonte. Its shares had risen by about 53 per cent thus far this yr earlier than immediately’s fall.
In a latest buying and selling replace, the corporate stated it anticipated adjusted earnings to be above the midpoint of its guided vary of £150m to £180m this yr. Whole energetic clients had been 16.4 million, in accordance with the replace for the yr to the top of August.
Mike Ashley’s Frasers Group is the most important shareholder in Asos, with an curiosity of roughly 29 per cent.
