Asos says it is investigating “unauthorised activity” involving third-party platforms it uses after customers received a notification from its app sent by hackers.
Dozens of people told the BBC they received the strange “ASOS HACKED” message from the clothing and beauty store’s app on Tuesday morning – with some saying it left them “scared” to open the app.
The notification was addressed to the company’s data protection officer and IT teams in what cyber security experts said looked like a “brazen” extortion attempt.
Asos acknowledged the “unauthorised customer notification” on Tuesday afternoon, saying some “basic personal information” may have been accessed.
In an email to customers on Tuesday night, the company apologised and urged customers not to engage with the notification. And it said the website and app are “operating as usual” promising customers they can “shop with confidence” while it investigates the incident.
The company has not as of yet informed the UK’s data watchdog, the Information Commission’s Office (ICO), about any breach.
Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google’s Play store says the ASOS app has been downloaded to android devices more than 10 million times.
The British retailer has a substantial global footprint – serving around 17 million customers each year across more than 150 markets.
Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.
Hackers seeking to pile pressure on potential victims by informing their customers is rare, as most extortions happen in private, so this incident may go down as a significant moment in cyber-attack history.
Shares in the company fell by around a tenth on Tuesday.
Charlotte Wilson, head of enterprise at cyber-security firm Check Point, called it a “deeply serious” and “brazen” attack whereby the hackers had apparently “turned Asos’ own app into their ransom note”.
But she told the BBC that Asos customers should not be “scared and frightened” – encouraging those worried to change their passwords, avoid clicking on the notification’s link and be cautious about possible scam emails or texts.
“My main concern is that my information, such as bank information, home address, telephone number, has been compromised,” said Erin, a student at the University of Sheffield.
She told the BBC that while her friends have expressed similar concerns about a potential data leak, her sister did not receive the notification on the Asos app.
“So the question is what is the extent? Are all customers affected even if they didn’t get the notification? It’s poor from Asos on all fronts.”
Asos said in its statement that it took “immediate action to restrict access to the notification platforms” on Tuesday – adding it was working with specialists within and outside the company, as well as relevant authorities.
It said it does not believe payment-card information or account passwords were impacted, and that its site and app are “operating as normal”.
“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate,” it said.
The BBC understands the National Cyber Security Centre has offered assistance to Asos.
Meanwhile Snowflake – whose tools are used by dozens of firms to collect, analyse and store data – told the BBC its investigation was ongoing, but it had so far found “no compromise” of its platform.
The company’s services have, however, been the subject of many high profile data breaches in recent years.