ASOS Admits Millions of Customer Details Stolen in Cyberattack
Translated & summarized from Calcalist by baba
Online fashion retailer ASOS has confirmed a cyberattack resulted in the theft of millions of customers' personal details, including names and contact information. The company initially downplayed the breach but later admitted the extent of the data compromised. ASOS is warning customers of potential phishing scams but assures that financial information was not stolen. The investigation is ongoing, and while ASOS advises no action, experts recommend password changes.
The story in 6 lines · by baba
- ASOS confirmed a cyberattack compromised personal details of millions of its global customers.
- Hackers accessed names, addresses, phone numbers, emails, and customer numbers.
- The stolen data could be used for phishing scams, ASOS warned.
- ASOS stated that bank account details and passwords were not stolen.
- The company is investigating the breach, which may have started with an employee account.
- Cybersecurity experts advise customers to change their passwords as a precaution.
Online fashion retailer ASOS has confirmed it was the victim of a cyberattack, admitting that hackers gained access to personal details of millions of users worldwide, according to a BBC report. The admission follows reports earlier this week from thousands of customers, including in Israel, who received app notifications about a breach.
Initially, ASOS suggested only "basic contact details" were likely stolen. However, the company has now acknowledged that names, addresses, phone numbers, email addresses, and customer numbers are in the hands of the hackers. Information about customer searches on the website was also compromised, which could facilitate targeted phishing scams.
ASOS is warning customers about potential impersonation fraud but stated that bank account details and passwords were not taken. "Please remain vigilant for unexpected messages or phone calls claiming to be from ASOS," the company advised. "We will never ask you to share your password, security code, or payment details via an unsolicited message or phone call."
The company is continuing its investigation into the incident. The prevailing theory is that hackers gained access to an employee's account by impersonation to obtain necessary passwords, subsequently downloading customer data. While ASOS advises customers that no action is required, cybersecurity experts recommend changing passwords as a precautionary measure.
"We know our customers trust us with their information," ASOS stated on its website. "We take this responsibility seriously and have already taken further steps to strengthen security." ASOS has 17 million customers globally, operates in over 150 countries, and employs 2,800 people.