Local Chorus
Местные новости из местных источников на вашем языке.

Translating into Русский. The English version is shown until it is ready.

Развивается

ASOS Probes Unauthorised Push Notification Claiming Its Systems Were Hacked

🇺🇸 США, London 21:28 IT и софт Бизнес2 Техно обновлено 6 ч назад первым сообщил Business Insider

Коротко

ASOS customers received a push notification titled “ASOS HACKED” at around 10 a.m. on Tuesday, claiming the retailer's systems had been compromised and threatening to leak data. ASOS said it is investigating unauthorised activity involving third-party platforms, has restricted access to its notification platforms and is working with advisers and authorities. The company said names and contact details may have been accessed but that it does not believe payment-card information or passwords were affected.

Читать полностью 2 мин чтения

ASOS said an unauthorised push notification was sent to customers of its mobile app at around 10 a.m. on Tuesday. The notification, titled “ASOS HACKED”, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” and included a link to a Telegram channel, according to the retailer and to screenshots posted to social media. [ 1 , 2 , 3 ]

In statements to the outlets, ASOS said it was investigating “unauthorised activity involving third-party platforms that we use to communicate with customers”, that it had taken immediate action to restrict access to the notification platforms, and that it was working with internal and external specialist advisers and all relevant authorities. The company said basic personal information including names and contact details may have been accessed, while it does not believe payment-card information or account passwords were impacted. It said its website and app were operating as normal. [ 1 , 2 , 3 ]

ASOS also said it has cyber security insurance with a large global provider, including business continuity insurance, and that it is too early to quantify any potential impact on trading. The company said customer trust was “incredibly important” and that an update would be provided if the situation changed, Newsweek reported. [ 1 ]

Engadget, citing The Guardian, reported that the Telegram channel linked in the message claimed to be operated by Xuanye Group, a name it said was largely unknown in cybersecurity circles. Snowflake, the cloud-data company named in the notification, told Business Insider it had begun an investigation after learning of the message and had found no compromise of the Snowflake platform at that time. [ 2 , 3 ]

Newsweek reported that around the same time as the notification, hundreds of users reported issues accessing the retailer's website and app, according to outage-tracking service Downdetector. Newsweek said it remained unclear whether customer data had been compromised, what information might have been accessed, or whether the message was sent by hackers who had gained access to ASOS systems, adding that ASOS had not provided a full explanation of what happened. [ 1 ]

Business Insider noted the incident appeared to be the latest in a string of cybersecurity attacks on UK-based companies, pointing to a ransomware attack last year that shut down Jaguar Land Rover production for five weeks and a hack that led Marks & Spencer to shut its online store. [ 3 ]

Почему это важно

The incident tests how retailers handle data held by outside vendors, since ASOS said the activity involved third-party notification platforms and named a cloud-data provider in the message. Other UK companies have recently suffered costly cyberattacks, and the documents say ASOS has cyber security and business continuity insurance but that it is too early to quantify any impact on trading. For shoppers, the open question is whether personal contact data was actually taken.

Ключевые факты

  • A push notification titled “ASOS HACKED” was sent to ASOS customers' phones at around 10 a.m. on Tuesday. [ 1 , 3 ]
  • The message said ASOS's “Snowflake instance” had been fully compromised and threatened to leak it unless the sender was engaged, and included a link to a Telegram channel. [ 1 , 2 , 3 ]
  • ASOS said it is investigating unauthorised activity involving third-party platforms used to communicate with customers and has restricted access to those platforms. [ 1 , 2 , 3 ]
  • ASOS said basic personal information including names and contact details may have been accessed, but that it does not believe payment-card information or account passwords were affected. [ 1 , 2 , 3 ]
  • ASOS said its website and app were operating as normal. [ 1 , 2 , 3 ]
  • Snowflake said it began an investigation after learning of the notification and had found no compromise of its platform. [ 3 ]
  • ASOS said it has cyber security insurance with a large global provider, including business continuity insurance, and that it is too early to quantify any potential impact on trading. [ 1 ]
  • Around the same time as the notification, hundreds of users reported issues accessing the ASOS website and app, according to outage-tracking service Downdetector. [ 1 ]

Подтверждено несколькими источниками

  • ASOS confirmed an unauthorised customer notification was sent to customers and that it is investigating unauthorised activity involving third-party platforms. [ 1 , 2 , 3 ]
  • ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external specialist advisers and relevant authorities. [ 1 , 2 , 3 ]
  • ASOS said names and contact details may have been accessed, while it does not believe payment-card information or passwords were impacted. [ 1 , 2 , 3 ]
  • ASOS said its website and app were operating normally. [ 1 , 2 , 3 ]
  • The notification stated that ASOS's Snowflake instance had been fully compromised and threatened to leak it, and carried a link to a Telegram channel. [ 1 , 2 , 3 ]

Пока неясно

  • Whether customer data was actually compromised and what information, if any, was accessed. ASOS said personal information “may have been accessed”, and Newsweek reported it remained unclear whether customer data was compromised or what was accessed.
  • Who sent the message and whether the sender had gained access to ASOS systems. Newsweek reported it was unclear whether the message was sent by hackers who gained access to ASOS systems; Engadget, citing The Guardian, said the Telegram channel claimed to be operated by Xuanye Group, which it described as largely unknown in cybersecurity circles.
  • Whether the Snowflake platform was involved in the incident. Snowflake told Business Insider it had found no compromise of its platform, while ASOS said it was investigating unauthorised activity involving third-party platforms it uses to communicate with customers.
  • The financial impact on ASOS. ASOS said it was too early to quantify any potential impact on trading, and no figure was given.

Что пишут местные СМИ

Деловые СМИBusiness outlets treated the incident as a company and consumer story, leading with the alarming wording of the notification and the company's response, and repeating ASOS's statement that names and contact details may have been accessed while card data and passwords were not. One outlet added detail on ASOS's cyber security and business continuity insurance and said it was too early to quantify any trading impact, and another placed the event in a string of recent cyberattacks on UK-based companies. [ 1 , 3 ]
Технологические СМИTech coverage focused on the technical claim in the message, noting that it named a Snowflake cloud instance and describing the provider's role in push notifications and customer data, and highlighting the Telegram channel's claim to be operated by a group it said was largely unknown among cybersecurity specialists. [ 2 ]

Хронология, местное время

  1. A push notification titled “ASOS HACKED” arrives on ASOS customers' phones in London. [ 1 , 3 ]
  2. Around the same time, hundreds of users report problems accessing the ASOS website and app, according to Downdetector. [ 1 ]
  3. Snowflake says it has investigated and found no compromise of its platform, as reported by Business Insider. [ 3 ]