Asos confirms breach of customer data after hackers send rogue app notification
Asos confirmed hackers stole customer contact data from a Snowflake platform and sent a rogue app notification.
UK retailer Asos told the London Stock Exchange that attackers accessed a third-party platform used to communicate with customers and stole names and contact information. BBC reporting says the data also includes home addresses, phone numbers, email addresses, and profile notes such as website search queries. The intruders, calling themselves Xuanye Group, sent an unauthorized in-app notice saying data hosted on Snowflake was compromised and demanding engagement or they would leak it. Reports say they obtained login credentials by impersonating a trusted contact; Snowflake said its own systems were not breached, and the number of stolen records is unknown.
- Asos confirmed theft of customer names and contact information.
- Reporting adds addresses, phones, emails, and profile search notes.
- Xuanye Group used Asos app notifications to demand engagement or a leak.
- Credentials were reportedly obtained by impersonating a trusted contact.
- Stolen volume is unknown; Asos has about 17 million customers.
Full article408 words · extracted from techcrunch.com · click to collapse
UK fashion retail giant Asos has confirmed a data breach of its customers’ personal information after hackers used the company’s own app to notify users that the company had been compromised.
Asos said in a filing with the London Stock Exchange that hackers broke into a third-party platform hosting data that the company uses to communicate with customers.
The company said that names and contact information were taken in the breach.
BBC News reports that the stolen data includes home addresses, phone numbers, and email addresses, as well as notes relating to customer profiles, such as their website search queries.
Asos said the hackers sent an “unauthorised customer notification,” which many posted to social media. The notification addressed Asos’ data protection officer and IT department and said that the hackers “fully compromised” the company’s data hosted on Snowflake, a tech company that allows its corporate customers to analyze large amounts of data. “Engage with us, or we will leak it,” the notification reads.
By using the app’s own notification system to alert customers, the hackers are trying to pressure the company into engaging with them or risk having the stolen data published online.
The hackers reportedly broke into the Snowflake instance by “impersonating a trusted contact to obtain log in credentials,” reports Bleeping Computer. Snowflake said it had not experienced a breach of its systems. It’s unclear if the Asos-run Snowflake instance was protected with multi-factor authentication. It’s also not known how the hackers gained access to Asos’ system for sending in-app push notifications, which is often handled by a third-party service.
The hackers, who go by the handle Xuanye Group, have not indicated how much data they allegedly possess. Asos has 17 million customers, according to its website.
Earlier this year, fintech giant Betterment was compromised by hackers who used their access to the company’s third-party marketing platform to impersonate the company and send a crypto scam to its customers. The hackers also access customer names, email addresses, and phone numbers, among other data, during the breach.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.