Incident affecting ASOS customers
ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
However, the company has not confirmed the threat actor's claim that its Snowflake environment was compromised or disclosed how many customers may be affected.
Engage with us, or we will leak it." Numerous other ASOS customers also reported receiving the same notification on Reddit, indicating that the message reached many, if not all, mobile app users.
See our data breach guidance for information on what you should do when you are affected by an incident like this.
If you are an ASOS customer, you should assume you are affected by this incident, even if you did not receive the unauthorised notification.
Look out for suspicious messages, which can arrive some time after a data breach incident.
The company has said it does not believe payment card information or account passwords were affected.
The company is investigating the unauthorised activity and has stated that basic personal information including name and contact details may have been accessed .
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
What happened
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
What changed
However, the company has not confirmed the threat actor's claim that its Snowflake environment was compromised or disclosed how many customers may be affected.
Engage with us, or we will leak it." Numerous other ASOS customers also reported receiving the same notification on Reddit, indicating that the message reached many, if not all, mobile app users.
Who is affected
See our data breach guidance for information on what you should do when you are affected by an incident like this.
If you are an ASOS customer, you should assume you are affected by this incident, even if you did not receive the unauthorised notification.
Why it matters
Look out for suspicious messages, which can arrive some time after a data breach incident.
The company has said it does not believe payment card information or account passwords were affected.
Response
The company is investigating the unauthorised activity and has stated that basic personal information including name and contact details may have been accessed .
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Attribution
NCSC-UK: ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
BleepingComputer: UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
What to watch next
Watch for updated vendor guidance and fixed-version details.