Top 5 This Week

Related Posts

Asos investigating after thousands of customers get notification saying retailer has been hacked – business live | Business

Asos investigating after thousands of customers get notification saying retailer has been hacked

Sarah Butler

Sarah Butler

Asos is investigating after users of its phone app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data.

The value of Asos’s shares on the London stock exchange dived almost 12%, after thousands of customers received a mobile app notification titled “Asos hacked” which sent them to a message on the Telegram messaging service.

However, the website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place.

The message was sent out to customers said “Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”

Snowflake is a cloud platform used to store, process and analyse data collected by Simon AI including transactions and demographic information, such as clothing sizes and body measurements. It also enables push notifications to clients’ phones.

Dray Agha, senior manager of security operations at Huntress, an online security firm, said:

double quotation markSnowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the ASOS mobile app also. This is clear public extortion.

Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.

The potential hack comes after a string of British retailers including Marks & Spencer, the Co-op and Harrods suffered major hacking events last year. M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean.

Share

Updated at 

Key events

Marie Wilcox, vice president of market strategy at the automated cyber investigation platform Binalyze, said:

double quotation markThis notification was psychological warfare, designed to whip up panic. Attackers know that any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response.

This is a clear shift in how we see breaches: from learning after the fact, to thousands of users seeing the news pushed onto their phone home screens in real time.

The next few hours are crucial. Asos cannot let panicked pressure dictate its response. The priority must be investigation, and closing the gap that allowed this mass notification to go out. Activity like this will surely have huge noise around it that leaves a clear trail, so there should be plenty of evidence of what happened and how to fix it.

This is also further evidence of the pressure security teams are under. They are overloaded: 15% of security alerts have to be flat-out ignored, 37% of vulnerabilities go undiscovered, and the focus is so totally on alerts and response that teams cannot proactively hunt threats before they strike. In this environment something will inevitably break through.

Share



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Popular Articles