Asos said it is still investigating the data breach and it would “contact customers directly where we believe additional information, support or action may be required”.
The UK fashion site explained to customers that hackers gained access to an Asos employee account by “impersonating a trusted contact to obtain log in credentials”.
With that log in to an unnamed service, the hackers were able to download the customer data.
In the pop up notification send to customers by the hackers, they claimed they had “compromised the Snowflake instance”.
Snowflake is a popular data storage and analysis company whose customers have been breached in the past due to unauthorised log ins.
The cyber criminals, calling themselves Xuanyewen, claimed to the they used a platform which is built natively on top of Snowflake – called Simon AI – to gain access to the data.
Simon AI has been contacted for comment. Snowflake previously said its platform had not been breached.
Asos said customers are not being asked to take any action.
But cyber security experts have warned users to change passwords as a precaution and be on alert for suspicious activity.
“Passwords have not been stolen, so be highly suspicious of any unsolicited text or email asking you to change or share yours,” said Trevor Dearing, Senior Director of Critical Infrastructure at Illumio.
“Expect scammers to mention the attack, use your personal details to seem genuine, and create urgency, such as threatening to lock your account within 24 hours.”
Asos said its website and app are safe to use and “we know our customers trust us with their information”.
“We take that responsibility seriously and have already taken additional steps to further strengthen security controls,” it said.
