UK's ASOS says cyber hack accessed customers' personal data

UK's ASOS says cyber hack accessed customers' personal data

​British online fashion retailer ASOS ​said on Thursday that a ‌cybersecurity breach ​earlier this week had exposed some customers' personal information, including names and contact details, according to its initial ‌investigation.

It said the hacker also had access to "certain non-personal account related information," but no payment card information or account passwords, ASOS said in an email to ‌customers. "We discovered that an unauthorised party gained access to an ASOS employee ‌account by impersonating a trusted contact to obtain log in credentials," ASOS said.

"Those credentials were then used to access information on certain third-party platforms used by ASOS." It said the affected ⁠platforms ​were immediately locked ⁠down, ensuring that no further information could be accessed, adding that the ASOS website and app ⁠were safe to use throughout, and remain safe to use.

ASOS said it is working ​with the relevant law enforcement and regulatory authorities. Shares in ASOS were up ⁠3%, paring losses for the week to 8%.

So-called "social engineering" operations, where hackers impersonate workers to ⁠gain ​access to companies' computer networks, are prevalent. British companies and institutions have been increasingly hit by aggressive and regular cyber and ransomware attacks in recent ⁠years. The British Library, a blood testing service, the London Underground, Marks & Spencer, the ⁠Co-op and Jaguar ⁠Land Rover are some that have suffered months of disruption due to such breaches.

Give Feedback

Use this form for editorial or site feedback. We usually reply within 2 to 3 working days.

By submitting, you agree that we may use your email address to respond.