Asos is investigating after users of its phone app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. The value of Asos’s shares on the London stock exchange dived almost 12%, after thousands of customers received a mobile app notification titled “Asos hacked” which sent them to a message on the Telegram messaging service. However, the website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place.
The message was sent out to customers said “Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.” Snowflake is a cloud platform used to store, process and analyse data collected by Simon AI including transactions and demographic information, such as clothing sizes and body measurements. It also enables push notifications to clients’ phones. Dray Agha, senior manager of security operations at Huntress, an online security firm, said: Snowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim.
The push notification suggests attackers have breached the systems controlling the ASOS mobile app also. This is clear public extortion. Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation.
I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach. The potential hack comes after a string of British retailers including Marks & Spencer, the Co-op and Harrods suffered major hacking events last year. M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean.
Extract — continue reading at the source.