LONDON, Oct 8 (Reuters) - British online fashion retailer ASOS said on Thursday that a cybersecurity breach earlier this week had exposed some customers' personal information, including names and contact details, according to its initial investigation.
It said the hacker also had access to "certain non-personal account related information," but no payment card information or account passwords, ASOS said in an email to customers.
"We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," ASOS said.
"Those credentials were then used to access information on certain third-party platforms used by ASOS."
It said the affected platforms were immediately locked down, ensuring that no further information could be accessed, adding that the ASOS website and app were safe to use throughout, and remain safe to use.
ASOS said it is working with the relevant law enforcement and regulatory authorities.
Shares in ASOS were up 3%, paring losses for the week to 8%.
So-called "social engineering" operations, where hackers impersonate workers to gain access to companies' computer networks, are prevalent.
British companies and institutions have been increasingly hit by aggressive and regular cyber and ransomware attacks in recent years. The British Library, a blood testing service, the London Underground, Marks & Spencer, the Co-op and Jaguar Land Rover are some that have suffered months of disruption due to such breaches.
(Reporting by Yadarisa Shabong in Bengaluru and James Davey in London; Editing by Vijay Kishore and William James)
