ASOS Investigates Suspected Cyberattack After Ransom Demands Sent to Customers
Translated & summarized from Calcalist by baba
Online fashion retailer ASOS is investigating a potential cyberattack after customers worldwide received app notifications claiming hackers accessed personal data and sent ransom demands. The incident caused ASOS's stock to drop 11%, and cybersecurity experts warn of aggressive extortion tactics and potential phishing risks.
The story in 5 lines · by baba
- ASOS is investigating a suspected cyberattack after customer data breach claims.
- Customers received app notifications with ransom demands via Telegram.
- The incident caused ASOS's stock to plummet 11% in London.
- The alleged attack involved the Snowflake cloud data platform.
- Experts warn of aggressive extortion and potential phishing scams.
Online fashion retailer ASOS is investigating a potential breach of its systems after thousands of customers, including those in Israel, reportedly received messages indicating a cyberattack. The British company's statement followed global customer reports of app notifications claiming hackers had infiltrated the company's computers and accessed personal information. The notification directed customers to a separate Telegram account. Following the incident, ASOS's stock price fell by 11% in London trading, marking the steepest decline among companies listed on the FTSE 250 index. The company's website and app appear to be functioning normally as investigations continue into whether a breach actually occurred. If confirmed, ASOS would join a list of British retailers, such as Marks & Spencer and Harrods, that have experienced similar cyberattacks in recent years.
The alert received by ASOS customers referenced Snowflake, a cloud platform used for storing, processing, and analyzing data, including customer transaction details and demographic information like clothing sizes. Snowflake also facilitates sending messages directly to customers' phones. "Snowflake is a huge database in the cloud where retailers store sensitive customer information. This is a real cause for concern if cybercriminals have indeed managed to penetrate it as they claim," Dror Eig, a senior manager at online cybersecurity company Hunters, told The Guardian. "The push notification suggests the attackers also breached the systems controlling ASOS's app, which is a clear public extortion." Eig added, "Sending a ransom demand directly to consumers' devices is an aggressive extortion tactic designed to pressure the company into quickly opening negotiations. I strongly advise shoppers to be wary of targeted phishing attempts until we receive official confirmation that a breach of the databases has indeed occurred."
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 1Right 2Haredi 1Other 2
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
