Skip links

ASOS App Users Targeted: Hackers Send Unauthorized Notifications

Asos has launched an investigation into what it describes as “unauthorized activity” involving third-party platforms, after customers of the online retail giant received alarming notifications from its app, reportedly sent by hackers. The unsettling “ASOS HACKED” messages appeared on Tuesday morning, prompting numerous users to share their concerns and fears about the security of their accounts.

The notifications were directed at Asos’s data protection officer and IT teams, with experts in cybersecurity labeling the incident as a bold extortion attempt. Recognizing the severity of the situation, Asos confirmed the unauthorized notifications, indicating that some basic personal information related to customers might have been compromised.

In a communication issued to customers on Tuesday evening, the company extended its apologies while advising users against engaging with the dubious notification. It reassured patrons that both the website and app were functioning normally, encouraging them to “shop with confidence” during this investigation.

Asos has yet to reach out to the UK’s data protection authority, the Information Commissioner’s Office (ICO), regarding any potential breach notifications. The full extent of the notifications remains unclear, but according to the Google Play Store, the ASOS app has received more than 10 million downloads on Android devices.

The British retailer serves approximately 17 million customers globally across over 150 markets, with reports indicating that users in countries such as Australia, France, Sweden, and the Republic of Ireland also received the alarming alerts.

Typically, hackers prefer to exert pressure on victims through private means, so this public notification tactic marks a significant shift in cyber extortion methods. Charlotte Wilson, head of enterprise at cybersecurity firm Check Point, described the incident as a “deeply serious” event, emphasizing that the hackers effectively transformed Asos’s app into their ransom note.

Conversely, Wilson reassured concerned customers that they need not panic, recommending that they change their passwords, refrain from clicking on links in the notification, and stay vigilant about potential phishing emails or texts.

The incident has already had tangible repercussions, with Asos’s shares dropping nearly ten percent on the same day.

Editor’s Take

This incident underlines the increasing risks faced by businesses in the face of cyber threats. The public nature of the notification not only heightens consumer concern but also raises questions about company protocols in handling data security. For users and businesses alike, the importance of vigilance and protective measures cannot be overstated in today’s digital landscape.

Source: www.bbc.co.uk

Leave a comment