WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

ASOS: Hackers tricked way into employee account before sending rogue push notification

Detailed view of network cables plugged into a server rack in a data center.
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.” The company’s explanation came two days after customers received an alert from ASOS’ own app claiming it had been hacked.

ASOS said login credentials obtained through the duped ASOS employee’s account “were then used to access information on certain third-party platforms.” ASOS did not say how many customers were affected nor whether it believed data had been copied out of its systems.

Shares in the business fell more than 10% on the London Stock Exchange and remained down by more than 9.5% from their value before the alert. The original notification linked to a Telegram channel run by an entity calling itself Xuanye Group. It claimed the attackers had compromised the company’s Snowflake cloud data environment.

Key facts

  • The company said its investigation, carried out with external experts, — found: the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.”

Sources & evidence