Asos hit by extortion hack that may have compromised some customer data

The attackers sent a push notification to Asos shoppers announcing their activity.

Photo of a smartphone open to the Asos website. The retailer's logo is displayed in black on a slightly off-focus white backdrop behind the phone.Bangla press/Shutterstock

UK-based fashion retailer Asos is doing damage control after its customers were sent a push notification claiming that its cloud services had been hacked. According to , Asos users received mobile alerts that were addressed to the company's data protection officer and IT personnel.

The notifications read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it." Snowflake is a cloud service that handles push notifications as well as managing data about transactions and customer demographics. A link in the message sent users to a Telegram channel claiming to be operated by Xuanye Group, a reportedly unknown name among most cybersecurity circles.

According to the company's statement, "We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."

Asos said that although customers' names and contact information may have been accessed in the hack, it did not believe payment details or passwords had been compromised. The company added that its app and website were operating as usual.

Original source Asos hit by extortion hack that may have compromised some customer data

Back to home