ASOS confirms customer data accessed following employee account compromise

ASOS confirms customer data accessed following employee account compromise

Online fashion retailer ASOS has confirmed that an unauthorised third party gained access to an employee account through a social engineering attack, potentially exposing customers’ personal information. The company said no payment card details or account passwords were accessed and that its website and app remain secure.

Online fashion retailer ASOS has confirmed a cybersecurity incident in which an unauthorised third party gained access to an employee account, potentially compromising customers’ personal information.

In a communication to customers, the company said the incident occurred on October 6 and involved an attacker impersonating a trusted contact to obtain an employee’s login credentials.

The compromised credentials were subsequently used to access information on certain third-party platforms used by ASOS.

The retailer said it immediately locked down the affected platforms to prevent further unauthorised access and launched an investigation with support from internal and external cybersecurity specialists.

According to ASOS, its investigation found that the attacker may have accessed personal information, including customer names and contact details, alongside certain non-personal account-related information.

However, the company stressed that no payment card information or account passwords were accessed during the incident.

ASOS also confirmed that its website and app were not affected by the breach and remained safe for customers to use.

The company said its investigation had been underway for 48 hours at the time of its communication, although a full assessment of the incident could take several weeks.

ASOS has advised customers to remain vigilant against unexpected messages or calls claiming to originate from the company, particularly those requesting personal information.

The retailer emphasised that it would never ask customers to disclose passwords, security codes or payment details through unsolicited messages or calls.

ASOS said it was continuing to work with relevant law enforcement and regulatory authorities as part of its investigation.

The company also confirmed that it would contact customers directly where it determined that additional information, support or action might be required.

The full extent of the incident, including the number of customers potentially affected, has not yet been disclosed.

ASOS said it was taking responsibility for the incident and had already implemented additional measures to strengthen its security controls.

Browse our latest issue

Intelligent CISO

View Magazine Archive