AI News Feed
Market watch
Cybersecurity

Asos Confirms Customer Data Breach After Hackers Send Rogue App Notification

Asos confirmed a data breach after hackers used its app to notify customers. Names and contact details were taken.

Asos said in a filing with the London Stock Exchange that hackers broke into a third-party platform hosting data the company uses to communicate with customers. The company said names and contact information were taken in the breach. BBC News reports that the stolen data includes home addresses, phone numbers, and email addresses, as well as notes relating to customer profiles, such as website search queries.

Asos said the hackers sent an “unauthorised customer notification,” which many users posted to social media. The notification addressed Asos’ data protection officer and IT department and said the hackers “fully compromised” the company’s data hosted on Snowflake, a technology company that allows corporate customers to analyze large amounts of data. “Engage with us, or we will leak it,” the notification reads.

By using the app’s own notification system to alert customers, the hackers are trying to pressure the company into engaging with them or risk having the stolen data published online.

The hackers reportedly broke into the Snowflake instance by “impersonating a trusted contact to obtain log in credentials,” according to Bleeping Computer. Snowflake said it had not experienced a breach of its systems. It is unclear whether the Asos-run Snowflake instance was protected with multi-factor authentication. It is also not known how the hackers gained access to Asos’ system for sending in-app push notifications, which is often handled by a third-party service.

The hackers go by the handle Xuanye Group. They have not indicated how much data they allegedly possess. Asos has 17 million customers, according to its website.

Earlier this year, fintech giant Betterment was compromised by hackers who used their access to the company’s third-party marketing platform to impersonate the company and send a crypto scam to its customers. The hackers also accessed customer names, email addresses, and phone numbers, among other data, during the breach.