Asos Shares Fall 10% After Hack Poses as Trusted Contact
Asos shares fell about 10% after hackers impersonating a "trusted contact" accessed customer names and contact details via an employee account, the retailer said.
By Grace Kim
2 min read
Updated
What's News
- Asos shares fell about 10% after the breach disclosure.
- Hackers impersonated a "trusted contact" to access an employee account.
- Customer names and contact details were exposed; payment details and passwords were not.
- Thousands of app users received a notification titled "Asos hacked" on Tuesday with a Telegram link.
Asos shares dropped by about 10% after the online fashion retailer disclosed that hackers accessed customer names and contact details by impersonating a "trusted contact" to break into an employee's account.
The London-listed company told customers that payment details and passwords were not compromised in the breach. The attack succeeded through a single employee account, which the hackers reached by posing as a contact the business already trusted.
What triggered the share slide?
Thousands of users of the Asos app received a notification on Tuesday titled "Asos hacked" containing a link to the Telegram messaging service, according to The Guardian. The notification — which pushed the breach into public view and sent the stock down roughly 10% — preceded the company's own account of what happened.
Asos has since confirmed the core facts of the incident:
- Hackers impersonated a "trusted contact" to gain access to an employee account.
- Customer names and contact details were exposed.
- Payment details and passwords were not compromised, the retailer said.
- The breach surfaced publicly via an unsolicited in-app notification linking to Telegram.
What does the breach change for customers?
For the customers affected, the exposure is limited to identity and contact data rather than financial credentials. Asos says payment details and passwords were untouched. Even so, names and contact details remain useful material for follow-on fraud, and the sudden in-app alert linking to Telegram shows how attackers can turn a data incident into a public market event in a single trading session.
The roughly 10% share decline gives the clearest measure of the market's initial verdict: investors treated the breach as material to Asos despite the absence of payment data in the exposure.
The company's explanation points to social engineering — a hacker posing as someone the business trusted — rather than a direct technical compromise of its systems. That distinction will shape how Asos reviews its internal verification practices around employee accounts.
The immediate question for Asos is whether the reputational and share-price damage can be contained now that the accessed data is confirmed as limited to names and contact details.
Source: The Guardian Business
More from Grace Kim
Show full bio
Market editor covering industry trends and analytics at Business Bearings.
607 articles