ASOS confirmed Tuesday that third-party platforms it uses to communicate with customers were accessed without authorization, after unauthorized push notifications were sent through its mobile app. The UK-based online fashion retailer said basic personal information, including names and contact details, may have been exposed. ASOS sells clothing, footwear, accessories and beauty products to customers worldwide, including in the United States.
The notifications began appearing at approximately 5:00 a.m. ET on Tuesday. The message told the company's data protection officer and IT staff that its Snowflake instance had been fully compromised and warned that the attackers would leak it unless ASOS engaged with them. Numerous ASOS customers reported receiving the same alert on Reddit, indicating it reached many, if not all, mobile app users.
ASOS is now displaying an in-app notice telling customers to disregard the unauthorized push alert and not to click or engage with the external third-party link it contained. The company has not confirmed the threat actor's claim that its Snowflake environment was compromised. It also has not disclosed how many customers may be affected. ASOS says it does not believe payment-card information or account passwords were impacted.
The notification directed ASOS to a Telegram channel operated by a threat actor calling itself the Xuanye group. In messages posted Tuesday morning, the group claimed the breach did not affect payment information. It later published a final statement saying it had stolen customer information and that the affected organization's app was safe to use. The group said the customer information was safe on its server and would not be touched for a designated period, and thanked ASOS for its clarity regarding the incident.
The group did not disclose what customer information was allegedly stolen, how many customers were impacted, or provide evidence that it had compromised ASOS's Snowflake environment. The threat actor's only contact point required payment, so further outreach was not pursued. ASOS has not confirmed the stolen-data claim or provided figures on affected customers.
More cybersecurity news from TechManNews.






