ASOS app users receive push notifications apparently sent by hackers
ASOS app users got hacker alerts from new Xuanye Group claiming a Snowflake compromise.
BBC reports that dozens of ASOS app users received a push notification addressed to the company's data protection officer and IT team, claiming hackers had fully compromised a Snowflake instance. The message links to a Telegram channel created the same day by a new group calling itself Xuanye Group, which has posted only three times. It is not confirmed that ASOS is a Snowflake customer or what data, if any, is stored there. Horizon3 said notification access is separate from Snowflake and, if both claims hold, suggests credentials opened more than one system.
- Xuanye Group opened Telegram the same day and posted about ASOS.
- App alerts imply access beyond the claimed Snowflake instance.
- Horizon3 said stolen credentials may have opened more than one system.
- ASOS's Snowflake relationship and any exposed data remain unconfirmed.
Full article289 words · extracted from bbc.co.uk · click to collapse
On social media, dozens of people have posted about receiving the message - confused as to what it means.
Although the apparent extortion message has been issued directly to customers, it is addressed to Asos' data protection officer (DPO) and IT team.
The message claims the unnamed hackers have "fully compromised the Snowflake instance".
This refers to the data storage company Snowflake, whose tools are used by dozens of firms for collecting, analysing and storing data.
It is not known if ASOS is a customer of Snowflake or what data, if any, is stored with the service.
But Snowflake has been the subject of many high profile data breaches in recent years and has been linked to incidents targeting services including Ticketmaster and Santander.
It is, however, very unusual for a data breach to be revealed quite so publicly - and for customers to be informed in this manner.
Most extortions and negotiations by cyber criminals are conducted in private, with hackers hoping their discretion will result in a quiet pay-off.
The pop up message contains a link to the hackers' Telegram channel.
The new group is calling itself Xuanye Group and only created its Telegram channel today.
They have posted only three times with the latest being about the ASOS hack.
Dan Bird, from cyber security firm Horizon3 says the pop up message the criminals sent implies that their access has gone beyond the Snowflake database.
"Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised."
"If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door," he said.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bbc.co.uk/news/articles/cj62ylzpr6d3o