

Asos says it is investigating “unauthorised activity” involving third-party platforms it uses after customers received a notification from its app sent by hackers.
Dozens of people told the BBC they received the strange “ASOS HACKED” message from the clothing and beauty store’s app on Tuesday morning – with some saying it left them “scared” to open the app.
The notification was addressed to the company’s data protection officer and IT teams in what cyber security experts said looked like a “brazen” extortion attempt.
Asos acknowledged the “unauthorised customer notification” on Tuesday afternoon, saying some “basic personal information” may have been accessed.
In an email to customers on Tuesday night, the company apologised and urged customers not to engage with the notification. And it said the website and app are “operating as usual” promising customers they can “shop with confidence” while it investigates the incident.
The company has not as of yet informed the UK’s data watchdog, the Information Commission’s Office (ICO), about any breach.
Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google’s Play store says the ASOS app has been downloaded to android devices more than 10 million times.
The British retailer has a substantial global footprint – serving around 17 million customers each year across more than 150 markets.
Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.
Hackers seeking to pile pressure on potential victims by informing their customers is rare, as most extortions happen in private, so this incident may go down as a significant moment in cyber-attack history.
Shares in the company fell by around a tenth on Tuesday.
Charlotte Wilson, head of enterprise at cyber-security firm Check Point, called it a “deeply serious” and “brazen” attack whereby the hackers had apparently “turned Asos’ own app into their ransom note”.
But she told the BBC that Asos customers should not be “scared and frightened” – encouraging those worried to change their passwords, avoid clicking on the notification’s link and be cautious about possible scam emails or texts.
