ASOS Shares Slide After Cyberattack Reports Raise Questions About Customer Data
ASOS shares fell sharply after reports of a cyberattack involving customer information and unauthorized notifications sent through third-party platforms.
ASOS shares fell sharply on October 6 after the British online fashion retailer disclosed a potential cybersecurity incident involving customer information and unauthorized notifications sent through third-party communication platforms.
The company restricted access to the affected systems and launched an investigation with internal and external experts as well as relevant authorities.
What ASOS has said about the cyberattack
ASOS said some basic personal information, including names and contact details, may have been accessed. The company said payment-card information and account passwords remained secure.
Its website and app continued operating, which suggests the incident was concentrated in connected systems rather than the core e-commerce platform.
Why third-party platforms create cybersecurity risk
Large retailers depend on cloud databases, marketing services, messaging tools and software vendors. Every connected system can become another path attackers may try to exploit.
Even when a company’s main website remains secure, stolen credentials or compromised integrations can expose customer information or allow attackers to misuse communication channels.
Hackers reportedly used customer notifications
Reports said customers received unauthorized messages referencing a breach. If attackers can send notifications through a company’s own channels, the incident can become especially damaging because recipients may initially trust the message.
That creates a secondary phishing risk. Criminals may try to exploit confusion by sending fake password-reset links, refund messages or account-security warnings.
Snowflake says its platform was not breached
A hacker group claimed it compromised ASOS data stored on Snowflake, but Snowflake said it found no evidence that its platform itself had been breached.
That distinction matters. Cloud services can be secure while customer accounts are compromised through stolen credentials, weak authentication or misconfigured access.
What customers should do
Customers should be cautious about unexpected messages, avoid clicking links in unsolicited account alerts and use unique passwords for different services. Multi-factor authentication should be enabled where available.
What to watch next
ASOS’s investigation will need to clarify exactly what data was accessed, how attackers entered the environment and whether additional customer notifications are required.
The incident follows a broader rise in attacks on companies that rely heavily on cloud and third-party platforms, reinforcing the need for strong identity management and vendor-security controls.
Source
Based on same-day reporting from Reuters.