
ASOS blames its data breach on a trick played on an employee
The retailer says an attacker posed as a trusted contact to obtain credentials; it still has not said how many customers were affected.
ASOS, the British online fashion retailer, has explained how its data breach happened. In its update on the London Stock Exchange, the company says a third party posed as "a trusted contact" to obtain an employee's credentials and used them to reach information held on outside platforms the retailer relies on. BleepingComputer reports the statement; this newsroom could not open the full announcement.
According to ASOS, the data accessed includes full names, contact details and some account information it does not consider personal. The company says payment cards and passwords were not touched. TechCrunch, citing the BBC, adds home addresses, phone numbers, email addresses and profile notes, such as searches on the site, in its coverage.
ASOS has not said how many customers or which countries are affected. A name and contact details are enough for phishing, a scam by message that imitates a company and cites the incident. ASOS asks customers, according to BleepingComputer, to be wary of unexpected messages or calls, and says it will never ask for passwords, security codes or payment details that way.
On Oct. 6 the app showed a fake alert, as this outlet reported. Addressed to the data protection officer and IT staff, it said the company's data in Snowflake, a cloud data service, was "totally compromised" and demanded: "Engage with us, or we will leak it." Snowflake told TechCrunch its own systems were not breached.
The group behind the alert, calling itself Xuanye Group, claims it took customer data and did not touch payment data. ASOS has not confirmed its identity or its claims.
It is still unknown whether the employee's account required a second authentication factor. TechCrunch says it is also unclear how the attackers reached the system that sends the app's notifications. ASOS says it is investigating with outside experts, police and regulators, without giving dates.


