ASOS says personal details may have been exposed after impersonation breach and fake app alert
A malicious actor impersonated a trusted contact to obtain login credentials to an employee account, gaining entry to third‑party platforms used by ASOS. The intrusion could have permitted access to customers’ names and contact information, though payment card numbers and passwords are believed to be safe. The breach came to light after a fraudulent push notification referencing Snowflake appeared in the ASOS mobile app, leading the company to block the notification service and start an investigation with internal and external security advisers and regulators.
Snowflake has said its platform shows no signs of compromise. ASOS has warned customers to disregard unexpected calls or messages and said its website and app remain functional. The episode has coincided with a share‑price drop of more than 10%.
How this was covered
- Coverage peaked at 11 outlets in a single hour
Why it matters
Potential exposure of shoppers’ personal details could lead to phishing attacks and erode trust in a major online retailer.
How this story developed
- Oct 6 ASOS alerts customers after hackers claim full breach of Snowflake data platform
- Oct 6 ASOS said payment card data and passwords are not thought to be compromised.
- Oct 8 Snowflake said its platform shows no evidence of compromise.
