ASOS: Hackers tricked way into employee account before sending rogue push notification
ASOS says attackers impersonated a trusted contact, hijacked an employee account, and accessed some customer contact data.
British retailer ASOS said attackers impersonated a trusted contact, took over an employee account, and used those credentials on third-party platforms before sending a rogue app push notification. The company said names, contact details, and some non-personal account data were accessed, but not payment cards or passwords, and it did not say how many customers were affected or whether data was copied out. A previously little-known group, Xuanye Group, claimed it hit ASOS’s Snowflake environment and the Simon AI service; Snowflake denied a breach, and the group has not publicly posted data samples. ASOS shares fell more than 10% after the alert.