Asos Investigates Extortion Hack After Push Notifications Threaten Data Leak
UK retailer Asos says it is investigating unauthorized activity on third-party notification platforms after attackers sent shoppers a push alert claiming a Snowflake cloud compromise and threatening to leak data.
According to The Guardian, the alerts were addressed to Asos's data protection officer and IT personnel. They read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it." The message included a link to a Telegram channel that claimed to be operated by Xuanye Group, a name that The Guardian reported is largely unknown in cybersecurity circles. Snowflake is a cloud service used for push notifications and for managing data about transactions and customer demographics, according to the report.
Asos said in a statement: "We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."
The company said customers' names and contact information may have been accessed in the incident, but it did not believe payment details or passwords had been compromised. Asos added that its app and website were operating as usual.