Breaking
DEMany dead - Russia attacks Ukraine on Putin's birthdayDEAward: French and Japanese win Nobel Prize in ChemistryDEMario Voigt gives up – Prime Minister accepts loss of his doctorateCRYPTO-ENWhy Abstract is killing its Ethereum L2 instead of launching a token to save itDE“We don’t have this border under control,” says the Labor Home Secretary about the English ChannelDEAfter the election: Talks about forming a government in Berlin continueCNXu Jiaqing's resignation was approved as Chairman of the Overseas Chinese Affairs Committee, with Li Yanhui acting as temporary replacementCNThe Jin Huye temple fair bomber was released after serving a 28-year sentence. Jiajian: There is a "time window" across jurisdictionsDEDeutsche Bahn: Three days of office duty: Railway employees approach their board of directors on the intranetKRCha Jeong-in "We may delay the announcement of the college entrance system reform plan... more public discussion is needed" (Comprehensive 2nd report)DEMany dead - Russia attacks Ukraine on Putin's birthdayDEAward: French and Japanese win Nobel Prize in ChemistryDEMario Voigt gives up – Prime Minister accepts loss of his doctorateCRYPTO-ENWhy Abstract is killing its Ethereum L2 instead of launching a token to save itDE“We don’t have this border under control,” says the Labor Home Secretary about the English ChannelDEAfter the election: Talks about forming a government in Berlin continueCNXu Jiaqing's resignation was approved as Chairman of the Overseas Chinese Affairs Committee, with Li Yanhui acting as temporary replacementCNThe Jin Huye temple fair bomber was released after serving a 28-year sentence. Jiajian: There is a "time window" across jurisdictionsDEDeutsche Bahn: Three days of office duty: Railway employees approach their board of directors on the intranetKRCha Jeong-in "We may delay the announcement of the college entrance system reform plan... more public discussion is needed" (Comprehensive 2nd report)
BackWhat you can do to protect yourself after Asos hacking message
What you can do to protect yourself after Asos hacking message
Urgent
BBC News50 minutes agoTech2 min read

What you can do to protect yourself after Asos hacking message

Online retailer emails customers after hackers send extortion attempt via app push notification.

Quick Look

  • Asos apologises after hackers hijacked its app to send push notifications threatening extortion.
  • The company restricts access and warns customers to ignore external links.

AI-generated summary

Why It Matters

Hackers sent unauthorised push notifications to Asos users attempting to extort the company over a Snowflake instance.

Font size

If a strange-looking message from Asos popped up on your phone on Tuesday, you may be worrying what it could mean and whether you need to do anything.

The online retailer has emailed customers apologising for the "unauthorised push notification" containing an external link, adding that they should disregard the message and not click on it.

Here's what has happened, and what those who may have been affected are being advised to do.

On Tuesday morning, Asos users across the UK were sent pop-up messages from its app that appear to have been sent by hackers trying to extort the company.

"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the message read.

Later that day, Asos said it took immediate action to restrict the apparent hackers' access, was investigating and working with advisers and relevant authorities on "next steps".

Data storage company Snowflake told the BBC its investigations had "found no compromise" of its platform.

At this stage it isn't clear what information, if any, has been accessed.

On Tuesday evening, Asos told customers it may include "basic personal information including name and contact details".

"However, we don't believe that any payment-card information or account passwords have been impacted," it added.

While those who received the pop-up message will undoubtedly be concerned, it does not mean your phone has been hacked.

According to Charlotte Wilson, head of enterprise at global cyber-security firm Check Point, "the biggest immediate risk may be what happens next".

She says criminals know people will be searching for information online and expects there to be "attempts to exploit that confusion".

Her advice to Asos customers is not to be "scared and frightened". But she says they should be "extremely suspicious" of emails, texts or messages claiming their account has been compromised, offering a refund or asking them to click a link to reset their password.

People should hang up the phone if they receive any calls from someone they think might be posing as Asos or another organisation, says Which? spokesperson Kat Cereda.

The consumer rights expert says they should contact the organisation themselves afterwards through separate means.

Open Questions

  • What specific information has been accessed?
  • How did the hackers gain access to send the notification?

Related Topics

This article was originally published by BBC News.

Related Stories

Intel wants to shake TSMC’s position? Foreign media point out the difficulties and expose cruel flaws
Developing·

Intel wants to shake TSMC’s position? Foreign media point out the difficulties and expose cruel flaws

Intel relied on its 18A process and U.S. manufacturing advantages to counterattack the semiconductor market, introduce new technologies and grab customers at low prices. However, in the face of TSMC's high yield experience and advanced packaging ecosystem, Intel 18A is likely to become the second source of supply in the short term. Whether it can truly turn around still depends on yield and external customer expansion.

自由时报
3 min read
More on this topicasos