Laura Gillespie, a data breach expert with Pinsent Masons, was commenting after ASOS confirmed it was investigating unauthorised third-party access to its database after UK customers received a notification yesterday morning claiming hackers had “fully compromised” its data.
Customers reported receiving a mobile app notification on Tuesday morning entitled ‘ASOS HACKED’ which directed them to click through to a Telegram account. The notification message referred to Snowflake, a data storage firm that is used by many major businesses, including other online retailers.
The notification said: “Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”
It is not clear how many customers may have been affected or exactly which of their personal or financial details may have been leaked. ASOS, which has 16.5 million customers and is active in more than 150 markets worldwide, apologised to customers in an email on Tuesday evening, conceding that personal information, such as names and contact details, “may have been accessed” as a result of the breach.
The retail giant urged customers to ignore and not engage with or click on any related links. It said that the website and app would be "operating as usual" as it investigates the incident. The retailer has said it does not currently believe that customers’ payment details or account passwords have been compromised and has not asked customers to reset their passwords.
Snowflake has said that it launched an investigation following the incident and has “found no compromise” of its data platform.
Gillespie said the incident served as a sobering reminder for business to identify potential vulnerabilities in their supply chain. “While the incident remains at a very early stage of investigation, some reports suggest that a third-party supplier may be implicated,” she said. “In our experience, there has been an upward trend in incidents arising from supply chain attacks, highlighting the need for organisations to consider not only their own cyber security posture, but also that of their suppliers.”
The incident is the latest cyber attack on a household name in the UK retail sector. Last year Harrods, Marks & Spencer and the Co-op all fell victim to ransomware attacks, where hackers typically access company systems to encrypt and steal data and demand a ransom in exchange for a decryption.
Gillespie said the breach also reinforced the need for businesses – and their third-party suppliers and platforms – to be alive to the increasingly sophisticated tactics deployed by hackers to inflict reputational damage and financial harm on businesses. “The confirmation that the threat actor sent push notifications to some app users also demonstrates how threat actors are diversifying their attack vectors,” she said. “In recent years, encryption and data exfiltration have been the primary methods used by threat actors, making this a potential evolution in attack methodology.”
The Information Commission's Office (ICO), the UK's data watchdog, has not commented publicly on the breach, but in the hours after the attack broke it did republish guidance for members of the public who might be concerned that an organisation has failed to keep their information safe.
The incident also comes just a week after a recent string of high-profile cyber attacks in Germany prompted legal experts there to issue a warning that such breaches could give to rise to potential mass claims for compensation.
Earlier this year, a data breach at Booking.com gave hackers unauthorised access to names, email addresses, phone numbers of customers and details about their past and present bookings. The online travel operator is already facing a Europe-wide mass class action over allegations that its use of ‘price parity’ clauses unfairly restricts accommodation providers.
Emily Cox, an expert in complex data privacy, media disputes and class action litigation at Pinsent Masons, said this latest attack would certainly turn up the heat on retailers’ response to these types of incidences. She added that it could also increase customer scrutiny on how well they feel businesses are handling these risks and how well they respond to concerns about customers’ personal data following a breach.
“This fact pattern is striking as customers will be left in no doubt from day one that an attack has taken place and that their apps were affected,” she said. “This will not afford the company any breathing room to investigate the circumstances before communicating with their customers. This publicity may also mean that any data protection claims, and indeed mass claims, follow on from the event much more quickly than usual.”