Online retailer ASOS has been the victim of a cyber attack from hackers calling themselves the Xuanye Group. A notification was sent by the group to the site’s customer base on 6th October claiming it had “fully compromised the Snowflake instance.” Snowflake is the company’s cloud-based data centre which also manages its push notifications.
On revealing the attack, the company’s shares dropped 10% overnight, however rallied slightly when markets opened on 7th October. This attack, while not seeming yet to have disclosed critical customer payment data, is deemed particularly aggressive by commentators as it took control of direct communication between the company and its customers. Experts suggest this could be a tactic to rush the business into a rapid negotiation with the hackers.
ASOS released a statement to its customers and shareholders, saying:
ASOS can confirm that, at around 10am today, an unauthorised customer notification was sent to ASOS customers.
We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.
Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.
Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.
The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.
The company is working to reassure customers that their personal data remains secure, however cyber crime experts have warned the public to be on the lookout for potential phishing attempts.
Claud Bilbao, VP, Underwriting and Distribution, Cowbell – a cyber insurance and resiliency company – notes that this won’t be the last large company to suffer one of these attacks. Much in the vein of the Coop or M&S before it, it will need more than insurance to maintain consumer trust in the face of an attack:
The damage to ASOS’ brand is still done, as the 10% slide in its shares overnight proves. This is just the latest in a long line of businesses that have been exploited by hackers bypassing the “front door” and, sadly, it won’t be the last.In this case, the company was able to continue trading but, from the initial confusion to the threat to release valuable customer data, this story is evidence that a cyber attack doesn’t have to take a business offline to do damage.



