Protect.Computer
NEWS

ASOS Confirms Breach After Hackers Sent 'ASOS HACKED' Alert

· 1 min read · Got hacked Identity theft
ASOS Confirms Breach After Hackers Sent 'ASOS HACKED' Alert

This follows our earlier report on the “ASOS HACKED” push notification. ASOS has now confirmed a data breach. The UK online fashion retailer says third-party platforms it uses to communicate with customers were accessed without authorization, and that basic personal information such as names and contact details may have been exposed. It does not believe payment-card information or account passwords were affected, and it is showing an in-app notice telling customers to ignore the unauthorized alert and not to click the external link it contained.

ASOS has not confirmed the attackers’ claim that they compromised its Snowflake environment, and has not said how many customers are affected. The notifications began around 5:00 a.m. ET on Tuesday and reached many app users. They pointed to a Telegram channel run by a group calling itself “Xuanye group.” The group later posted a “final statement” claiming it had stolen customer information and that it would not be touched “for a designated period,” but gave no details, numbers or evidence. BleepingComputer did not pay for access to the group’s contact point.

How to check if you’re affected

Affected products are the ASOS mobile app and ASOS customer accounts. Anyone who received the notification may have had their details exposed, though ASOS has not said how many people are involved. In the meantime:

  • Do not tap the link in the “ASOS HACKED” notification or engage with the Telegram channel.
  • Expect phishing emails or texts that use your name and contact details and mention ASOS, a “data leak” or a refund; ignore links in them and go to the ASOS app or site directly.
  • Change your ASOS password if you reuse it elsewhere, and watch for notices from ASOS.

Sources

Related reading