Asos Confirms Data Breach After Hackers Send Rogue App Notification
Key Takeaways
- Asos confirmed a data breach affecting customer names, contact info, and profile notes.
- Hackers sent an unauthorized push notification directly through the official Asos app.
- Attackers impersonated a trusted contact to steal login credentials for a Snowflake instance.
- The hacker group, calling themselves Xuanye Group, demanded contact under threat of leaking data.
UK fashion retail giant Asos has confirmed a data breach of its customers’ personal information after hackers used the company’s own app to notify users that the company had been compromised. Asos stated in a filing with the London Stock Exchange that hackers broke into a third-party platform hosting data that the company uses to communicate with customers. The company confirmed that names and contact information were taken in the breach.
Additional reports indicate that the stolen data includes home addresses, phone numbers, and email addresses, as well as notes relating to customer profiles, such as their website search queries. Asos noted that the hackers sent an unauthorized customer notification, which many users subsequently posted to social media platforms. The notification directly addressed Asos’ data protection officer and IT department, claiming that the hackers had fully compromised the company’s data hosted on Snowflake, a technology platform that allows corporate customers to analyze large amounts of data.
The threatening notification read that the company should engage with them or face a data leak. By utilizing the app’s own notification system to alert customers directly, the hackers attempted to pressure the corporate giant into engaging with their demands or risk having the stolen data published online for the public to see.
Reports indicate that the hackers, who operate under the handle Xuanye Group, broke into the Snowflake instance by impersonating a trusted contact to obtain login credentials. Meanwhile, Snowflake clarified that it had not experienced a direct breach of its own central systems. It remains unclear if the specific Asos-run Snowflake instance was properly protected with multi-factor authentication. Furthermore, it is not yet known precisely how the hackers gained access to Asos’ system for sending in-app push notifications, a function that is frequently handled by a specialized third-party service.
The group has not yet indicated the exact total amount of data they allegedly possess. Asos boasts an impressive base of 17 million active customers according to official company documentation. This incident echoes similar recent cyberattacks, such as an event earlier this year where fintech giant Betterment was compromised by hackers who used access to a third-party marketing platform to send fake scam notifications to users, accessing names, email addresses, and phone numbers in the process.
As organizations increasingly rely on complex webs of third-party platforms and software-as-a-service providers, supply chain vulnerabilities continue to present significant risks. Security experts emphasize the critical importance of robust credential management, strict access controls, and multi-factor authentication across all operational environments. Asos is continuing to assess the full scope of the incident while working to secure its digital infrastructure against further unauthorized access and to reassure its millions of customers regarding the safety of their remaining personal information.
Recommended for you
Tools and services we trust to boost productivity and content workflows.
Browse picks