ASOS: Hackers tricked way into employee account before sending rogue push notification
ASOS says attackers impersonated a trusted contact, hijacked an employee account, and accessed some customer contact data.
British retailer ASOS said attackers impersonated a trusted contact, took over an employee account, and used those credentials on third-party platforms before sending a rogue app push notification. The company said names, contact details, and some non-personal account data were accessed, but not payment cards or passwords, and it did not say how many customers were affected or whether data was copied out. A previously little-known group, Xuanye Group, claimed it hit ASOS’s Snowflake environment and the Simon AI service; Snowflake denied a breach, and the group has not publicly posted data samples. ASOS shares fell more than 10% after the alert.
- Attackers impersonated a trusted contact to take over an employee account.
- Names and contact details were accessed; cards and passwords were not.
- Xuanye Group claimed a Snowflake breach; Snowflake denied it.
- ASOS shares fell more than 10% after the customer alert.
Full article480 words · extracted from therecord.media · click to collapse
British online fashion retailer ASOS said Thursday that hackers gained access to an employee’s account by “impersonating a trusted contact,” allowing them to send an unauthorized push notification to customers. The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.” ASOS did not say how many customers were affected nor whether it believed data had been copied out of its systems. The company’s explanation came two days after customers received an alert from ASOS’ own app claiming it had been hacked. Shares in the business fell more than 10% on the London Stock Exchange and remained down by more than 9.5% from their value before the alert. ASOS said login credentials obtained through the duped ASOS employee’s account “were then used to access information on certain third-party platforms.” The original notification linked to a Telegram channel run by an entity calling itself Xuanye Group. It claimed the attackers had compromised the company’s Snowflake cloud data environment. The perpetrators repeated this claim to BBC News, adding that it had attacked the Simon AI service integrated with Snowflake. Snowflake has denied being breached, while Simon AI did not respond to a request for comment. ASOS said that no payment card information or account passwords were accessed, and that its website and app had been safe to use throughout. It told customers they did not need to take any action, but warned them to be wary of unexpected messages or calls claiming to be from the company, adding that it would never ask for passwords, security codes or payment details through an unsolicited message or call. The company said the affected platforms had been locked down and that it would contact customers directly if its investigation, expected to continue for several weeks, found they needed further information or support. Xuanye Group, a name not previously known to researchers who track extortion gangs, has published no samples of customer data to back up its claims — although it purportedly shared such data with BBC News. In posts on Telegram after the notification was sent, the group said payment information was not affected and claimed it would hold back the data it said it had taken for an unspecified period. “Once our investigation is complete, we will contact customers directly where we believe additional information, support or action may be required,” stated ASOS. “We know our customers trust us with their information. We take that responsibility seriously and have already taken additional steps to further strengthen security controls.”
No previous article
No new articles
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79