ASOS Confirms Data Breach After "HACKED" In-App Notifications
ASOS Confirms Data Breach After “HACKED” In-App Notifications
🚨 UK fashion retailer ASOS has confirmed a data breach after hackers sent unauthorized push notifications through its mobile app, claiming to have stolen customer data from the company’s Snowflake environment. ASOS, a large UK-based online fashion retailer, sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States.
ASOS has stated that third-party platforms used to communicate with customers were accessed without authorization. Basic personal information, including names and contact details, may have been exposed. The company is now displaying an in-app notice telling customers to disregard the unauthorized push alert and not to click or engage with the external third-party link it contained.
The notifications began appearing at approximately 5:00 a.m. ET on Tuesday. One notification read, “ASOS HACKED,” and stated, “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” Numerous other ASOS customers reported receiving the same notification on Reddit, indicating that the message reached many, if not all, mobile app users. The notification directs ASOS to a Telegram channel operated by a threat actor calling itself the “Xuanye group.”
In messages posted to the channel Tuesday morning, the threat actor claimed that the breach did not affect payment information. However, they later published a “FINAL STATEMENT,” claiming that they stole customer information in the attack. The group’s message stated: “The affected organisation’s app is safe to use. The incident involves customer information; it is safe on our server, and it will not be touched for a designated period.”
The Xuanye group did not disclose what customer information was allegedly stolen, how many customers were impacted, or provide evidence showing that it had compromised ASOS’s Snowflake environment. ASOS believes that payment-card information or account passwords were not impacted. Additionally, the company has not confirmed the threat actor’s claim that its Snowflake environment was compromised or disclosed how many customers may be affected.