ASOS Confirms Data Breach Linked to Stolen Employee Credentials
ASOS confirmed attackers used stolen employee credentials to access customer account data via third-party platforms.
UK retailer ASOS told customers on October 8 that personal and account data was accessed in an October 6 breach. The attacker impersonated a trusted contact to steal an employee’s credentials, then used them on third-party customer platforms and sent a push notification claiming a Snowflake compromise. ASOS said payment data was not taken and operations continued; Snowflake said its platform was not compromised. Actor Xuanye Group told the BBC a Simon AI instance was the access path, and a sample reportedly included names, contact details, customer numbers, and search history.
- Attacker impersonated a trusted contact to steal an ASOS employee login.
- Credentials were used on third-party platforms; payments and operations were unaffected.
- Xuanye Group pushed a notification claiming a Snowflake compromise, which Snowflake denied.
- A sample reportedly held names, contacts, customer numbers, and search history.
- Group-IB tied the new Telegram channel to earlier gaming-trading accounts.
Full article615 words · extracted from infosecurity-magazine.com · click to collapse
UK fashion retailer ASOS has notified customers the threat actor had accessed personal and customer account data following the October 6 data breach.
In the email to customers on October 8, shared with Infosecurity, ASOS also confirmed that payment information was not compromised and that the incident has not affected operations.
Upon investigating the breach, ASOS discovered that the attacker had gained access to an employee account “by impersonating a trusted contact to obtain log in credentials.”
These credentials were then used to “access information on certain third-party platforms used by ASOS.”
Access to Third-Party Platforms Enabled ASOS Attack
In a statement sent to the London Stock Exchange, published on October 6, ASOS said they are investigating third-party platforms which were used to communicate with customers.
Access to these platforms enabled the threat actor to send a legitimate-looking push notification to ASOS customers.
The notification, seemingly addressed to ASOS’s own data protection officer (DPO) and IT team, claimed that the attacker had compromised a Snowflake instance and asked the company to engage with them.
Snowflake is a cloud-based data platform that companies use to store, manage, analyze and share large amounts of data.
A Snowflake spokesperson told Infosecurity that the company began an investigation as soon as it became aware of the attacker’s push notification.
"At this time, we can report that we have found no compromise of the Snowflake platform," they added.
However, Pieter Arntz, senior malware intelligence researcher at Malwarebytes, suggested that an agentic marketing platform used by ASOS, known as Simon AI, may be indirectly linked to the incident because it is built on Snowflake Cortex AI.
Simon AI’s own website promotes its partnership with ASOS alongside American clothing brands Bombas and Equinox.
On October 8, the BBC reported a conversation cybersecurity reporter Joe Tidy had with the threat actor in which they said a Simon AI instance was compromised to gain access to the data.
American software firm Monetate, which acquired Simon AI in July, has been contacted by Infosecurity for comment.
More Than Basic Contact Details Could Be Exposed
In the Telegram channel which was linked to in the push notification claiming the hack, the attacker, using the name ‘Xuanyewen’ and ‘Xuanye group,’ said the incident only involves “customer information.” They claimed it “is safe on our server and will not be touched for a designated period.”
According to the BBC, a sample of the stolen data it was sent by the threat actor contained more information than the "basic contact details" ASOS had previously said may have been compromised.
These would include names, addresses, phone numbers, emails, customer numbers as well as searches customers have made on the website, with terms like "reclaimed vintage,” “glamorous wide fit” and “ASOS petite” allegedly appearing in the data.
The BBC did not mention whether the data shared by the threat actor has been analyzed by cybersecurity experts to assess their legitimacy.
This comes after Infosecurity reported that the Telegram account behind the rogue message may be linked to gaming trading activity.
Anastasia Tikhonova, global head of threat research at Group-IB, found that the Telegram channel included in the bizarre push notification sent to ASOS customers was brand new – created on October 6 – and that the Telegram account behind it previously carried other names, largely in gaming-item trading.
These include JohnCZ (@JohnCzwartacki) and Moon Transfers (@NFTmoonstock).
"Our instant messaging monitoring system retained historical changes to Telegram account display names and usernames. Those records show JohnCZ and Moon Transfers as earlier display names of the same account currently using @xuanyegroup, which is associated with the Xuanye Group Telegram presence," she further explained.
Image credits: Mamun_Sheikh / Burdun Iliya / Shutterstock.com