ASOS cyber attacked in apparent hack: Lessons and advice for businesses

This post was originally published on this site.

Customers of online retailer ASOS have received a push notification claiming that the company has been hacked.

The message said: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

In a statement, ASOS said:

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.

“Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.”

Reaction to the ASOS ‘hack’ and the lessons for businesses

Breno Oliveira, chief product Officer at payabl.: 

“ASOS is the latest in a string of high-profile cyber attacks on UK retailers.

“What makes this one stand out is that hackers turned the retailer’s own notifications into a ransom tool. Most attacks like this happen out of customers’ sight, but this one appeared directly on their phone screens.

“That goes to the heart of why trust matters so much in retail, how quickly it can be lost and how long it can take to rebuild.

“It’s also a reminder that the explosive growth of ecommerce has given hackers more avenues for attack. Apps, marketplaces, loyalty schemes and third-party data platforms all hold more personal data on consumers than ever. It’s a reminder to shoppers to always remain wary of any unexpected messages, whether by app notification, text or email.

“For retailers, the incident is a reminder that as the touchpoints with customers grow, so must their approach to security, covering every step of the customer journey from login to checkout.

“The latest innovations in real-time monitoring and AI-driven detection tools can help stop illicit activity before it becomes a crisis. Given the reputational and financial damage at stake, no retailer can afford to treat the security of their services as anything less than a priority.”

Andy Ward, SVP international at Absolute Security, said:

“It only takes one successful cyber attack or data breach for thousands, if not millions, of people to be put at risk. With the rise of AI, these threats are not only becoming smarter but faster, and it is inevitable that other UK businesses will face a threat at some point.”

“It is essential that UK businesses are prioritising cyber resilience to minimise disruption and potential downtime. With threats evolving faster than ever, organisations must implement real-time visibility into their IT environments to identify vulnerabilities, and respond to these incidents when they occur.”

Cyber security advice for small businesses

How to tighten security measures against cyber attacks

Cyber security compliance: What you need to know

The password combinations most likely to get you hacked 

Five tips to mitigate cyber-attacks in your business

Hot this week

Topics

spot_img

Related Articles

Popular Categories

spot_imgspot_img