Home › Technology › How can I protect my data after the ASOS hack and who...
Technology

How can I protect my data after the ASOS hack and who was affected?

How can I protect my data after the ASOS hack and who was affected?
Key Points

How can I protect my data after the ASOS hack and who was affected? Personal information, such as names and contact details, may have been accessed in the hack, the fashion retailer warned - Bookmark - CommentsGo to comments Become an Independent member to bookmark this article Already a member? Log in Fashion giant ASOS is investigating “unauthorised activity” involving a third-party platform after customers were sent a phone alert saying the online retailer had been hacked.

How can I protect my data after the ASOS hack and who was affected? Personal information, such as names and contact details, may have been accessed in the hack, the fashion retailer warned - Bookmark - CommentsGo to comments Become an Independent member to bookmark this article Already a member? Log in Fashion giant ASOS is investigating “unauthorised activity” involving a third-party platform after customers were sent a phone alert saying the online retailer had been hacked. Personal information, such as names and contact details, may have been accessed in the hack, according to the company. But the retailer, which has 16.5 million customers, said it does not “believe that payment card information or account passwords were impacted”. Some customers received a strange looking message from the retailer, leaving many concerned their personal details are at risk. Here is what happened and what to do next. What message did people receive? Some ASOS customers received an unauthorised push notification from ASOS on Tuesday October 6. "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the message read. The message was followed by a Telegram link. ASOS has emailed its customers apologising for the “unauthorised push notification" and urged customers not to click on the external link and to disregard the message. The notification message sent out by cyber attackers refers to cloud firm Snowflake, which stores data for many major companies. Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message. “The investigation is ongoing and we will provide further updates as soon as more information becomes available,” a spokeswoman added. The National Cyber Security Centre (NCSC), a part of GCHQ, has offered ASOS assistance. Who is affected? All ASOS customers should assume they are affected by this incident, even those who did not receive the push notification, NCSC said. But receiving a push notification doesn’t mean your phone has definitely been hacked. What can I do to protect myself following the attack? The incident is being investigated, but in the meantime the advice is: Don’t click any suspicious links: NCSC has urged customers to look out for suspicious messages, which may arrive some time after the breach incident. Cyber security experts and ASOS have also urged customers to not click on the Telegram link included on the push notification. Change passwords and security: Experts suggest updating passwords on your ASOS account as well as any accounts that share the same password. “Using passkeys, or strong, separate passwords plus two-step verification for your accounts will keep you secure even if your data is breached,” according to NCSC. Check online transactions: Although ASOS has said customer payment details and account passwords have not been affected. Cyber security experts suggest keeping an eye on any online transactions, especially if they look unusual. What should customers now look out for? Following the data breach criminals may capitalise on the breach's publicity with more phishing scams, Zain Javed, director of strategic growth and cyber services at Citation Cyber has warned. “Customers should be particularly suspicious of emails or text messages saying things such as ‘your ASOS account has been compromised’, ‘verify your account’, ‘reset your password’, ‘confirm your payment details’ or ‘claim compensation for the ASOS breach’,” he said. “We could also see fake delivery notifications, refund messages or discount vouchers designed to look as though they have come from ASOS. This is particularly effective after a genuine cyber incident because the criminal doesn't have to invent the story. Customers already know something has happened, so a message saying 'we're contacting you following yesterday's security incident' immediately feels more believable. “Anyone receiving a message like that should avoid the link and instead open the ASOS app or type the ASOS website address directly into their browser. ASOS itself advises customers that it will never ask for passwords or sensitive card information through social media and warns against unfamiliar links.” Join our commenting forum Join thought-provoking conversations, follow other Independent readers and see their replies Comments [Image text:] asos asos asos asos as osso
ASOS (ORG) Independent (ORG) Snowflake (ORG) Telegram (ORG) The National Cyber Security Centre (ORG) NCSC (ORG) GCHQ (ORG)
Originally published by The Independent UK Read original →