ASOS Says Hackers Impersonated a Trusted Contact to Take Over an Employee Account and Send a Fake Breach Alert
British online fashion retailer ASOS said on Thursday that hackers gained access to an employee's account by "impersonating a trusted contact". The attackers then sent an unauthorised push notification to customers through the company's own app, claiming ASOS had been hacked. ASOS said login credentials obtained through the employee's account were later used to access information on certain third-party platforms. Shares fell by more than 10% on the London Stock Exchange and remained down by more than 9.5% from their pre-alert value.
ASOS said its investigation, run with external experts, found that names, contact details and certain non-personal account related information were accessed. It said no payment card information or account passwords were taken, and that its website and app were safe to use throughout. It did not say how many customers were affected or whether data was copied out of its systems. The notification linked to a Telegram channel run by a group calling itself Xuanye Group, which claimed to have compromised ASOS's Snowflake environment. Snowflake has denied being breached, and the group has published no customer data samples, though it reportedly shared some with BBC News.
ASOS told customers they do not need to act, but should be wary of unexpected messages or calls claiming to be from the company. It said it would never ask for passwords, security codes or payment details this way. The affected platforms have been locked down, and the investigation is expected to continue for several weeks.