The online shopping giant ASOS has seemingly been hacked today, with customers receiving a threatening notification from the mobile app.
The message (titled “ASOS HACKED”) was sent on Tuesday morningus that “the potential scope is significant”. We’ve contacted ASOS, but so far it hasn’t publicly commented on the issue
You can follow all the latest developments live with us, including the latest advice on what you should do if you’re one of the site’s 17 million global customers…
- ASOS customers reported receiving a threatening alert on Tuesday morning
- The alert was titled ‘ASOS Hacked’ and linked out to a Telegram chat
- ASOS hasn’t yet officially commented on the security issue
What did the alert say?
ASOS customers first reported receiving the push alert above on Tuesday morning at around 4.55am ET / 9.55am BST.
This coincided with a spike in reports on Downdetector. The message is addressed to ASOS’ data protection officer (DPO) and IT team, but was sent to customers.
The ‘Snowflake’ the message refers to is a Software-as-a-Service (SaaS) that organizations use as a dedicated cloud environment to store, process, and analyze data. This is what has concerned security experts, although it’s a little early to say whether customer data has been compromised.
What should you do?
Did you get the ASOS ‘hacked’ notification? If so, there are a few important things that you shouldn’t do, including clicking the Telegram link in the message. You should also:
- Avoid clicking links in any suspicious emails
- Do not click links in any suspicious texts or messages
Other cybercriminals could try to exploit the hysteria caused by the ASOS notification, so you should be particularly wary of emails telling you your account has been compromised, or asking you to reset your password.
It’s also wise to be careful about shopping on ASOS until the company comments publicly on the issue, which hasn’t happened yet.
