Asos has confirmed that hackers accessed personal information belonging to its customers and then used the retailer's own app to notify users about the compromise. The U.K. fashion company said in a filing with the London Stock Exchange that the intruders broke into a third-party platform that hosts data Asos uses to communicate with customers. Names and contact information were taken in the breach, according to the company.
BBC News reported that the stolen data includes home addresses, phone numbers, and email addresses, along with notes tied to customer profiles such as website search queries. Asos said the hackers sent an unauthorized customer notification, which many recipients posted to social media. The notification addressed the company's data protection officer and IT department and claimed the hackers had fully compromised data hosted on Snowflake, a tech company that lets corporate customers analyze large amounts of data. The message told Asos to engage with the attackers or the data would be leaked.
By pushing the alert through the app's own notification system, the hackers appeared to be pressuring the company to open talks rather than risk publication of the stolen information. Bleeping Computer reported that the intruders got into the Snowflake instance by impersonating a trusted contact to obtain login credentials. Snowflake said it had not suffered a breach of its systems. It is not clear whether the Asos-run Snowflake instance was protected with multi-factor authentication, and it is also unknown how the hackers gained access to the Asos system used to send in-app push notifications, which is often handled by a third-party service.
The hackers operate under the handle Xuanye Group and have not said how much data they claim to hold. Asos has 17 million customers, according to its website. The company has not indicated how many of those customers were affected.
The incident echoes an earlier breach this year at fintech giant Betterment, where hackers used access to a third-party marketing platform to impersonate the company and send a crypto scam to its customers. In that case, the intruders also accessed customer names, email addresses, and phone numbers, among other data.
The breach puts a U.S. spotlight on Snowflake, the data cloud vendor whose corporate customers include American companies, and on the third-party services retailers rely on to communicate with shoppers.
More cybersecurity news from TechManNews.


