Fashion retailer Asos confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app, claiming to have stolen customer data from the company’s Snowflake environment. The notifications, sent around 10:00 BST, alerted customers to a “full compromise” of the Snowflake instance and threatened data leakage unless a ransom was paid. Asos acknowledged the “unauthorized customer notification” and stated that some “basic personal information” may have been accessed, but that payment card details and passwords were not believed to be impacted. The company has taken steps to restrict access to notification platforms and is investigating the incident, assuring customers its website and app are operating normally.
The hackers, identifying themselves as the Xuanye Group, used the Asos app to directly address the company’s data protection officer and IT teams, a tactic cyber security experts described as “brazen.” A link to the group’s Telegram channel was included in the notification. The Telegraph reported the hackers demanded a ransom payment in exchange for deleting customer information, giving Asos a two-week deadline to respond. Shares in Asos fell by around a tenth on Tuesday.
While Asos has not yet informed the UK’s data watchdog, the Information Commissioner’s Office (ICO), the incident has drawn attention for its unusual directness. Charlotte Wilson, head of enterprise at cyber-security firm Check Point, called it a “deeply serious” attack, but advised customers not to panic, suggesting they change passwords and be cautious of potential scam communications. Asos serves approximately 17 million customers in over 150 markets, and reports of the notification extended to users in Australia, France, Sweden, and the Republic of Ireland. The ASOS app has been downloaded more than 10 million times on Android devices alone.
Read the original coverage
💬 Comments
📜 Comment Policy