Asos Customer Data Compromised via Employee Account Breach
Asos confirmed a data breach involving customer contact information following the compromise of an employee account, though payment data remains secure.
Atlas Newsdesk ·
Unauthorized parties accessed customer names and contact details after compromising an internal employee account. The breach occurred when attackers impersonated a trusted contact to obtain login credentials, subsequently accessing third-party platforms utilized by the retailer.
While the company confirmed that payment card information and passwords remain secure, the incident resulted in a 10% decline in share value. The unauthorized group also accessed unspecified non-personal account data during the intrusion.
Management has secured the affected platforms and initiated investigations with law enforcement and regulatory bodies. Additional security controls have been implemented to mitigate further risk, though the company has advised customers to remain vigilant against potential phishing attempts.
Internal teams are currently conducting a comprehensive review to determine if further customer notification or support is required. No evidence suggests that the primary website or application infrastructure was directly compromised during the event.