Skip to content

Hackers Messaged Asos Shoppers From the Company's Own App: Addresses, Phone Numbers and Searches Stolen

1 min read
Share
Hackers Messaged Asos Shoppers From the Company's Own App: Addresses, Phone Numbers and Searches Stolen

Shoppers at British fashion giant Asos received an in-app notification the company didn't write. The message was addressed to the data protection officer and the IT department, and said the hackers had "fully compromised" the company's data stored on Snowflake. It ended with an ultimatum: "Talk to us or we'll publish it."

The company confirmed it had suffered a breach. In a filing to the London Stock Exchange, Asos said the attackers got into a third-party platform where the data it uses to communicate with customers is stored, and that names and contact details were taken. According to the BBC, the list is longer: home addresses, phone numbers, email addresses and notes from user profiles, including searches on the site.

How did they get in? According to Bleeping Computer, the hackers posed as a trusted contact and that's how they got hold of the Snowflake login details. Snowflake itself says its systems were not breached. It's not clear whether the Asos account was protected with multi-factor authentication, nor how the attackers reached the in-app notification system - which is often run by another, outside firm.

The group signs itself Xuanye Group and so far isn't saying how much data it has. Asos, for its part, lists 17 million customers on its website. They weren't the real recipients of the message - they were a megaphone to pressure the company into negotiating.

The scenario isn't new. Earlier this year fintech company Betterment was attacked in a similar way: hackers used an outside marketing platform to send customers a fake crypto offer in the company's name. The pattern is the same - you don't attack the fortress, you attack the supplier who has a key to the back door. How many of the online shops we order from keep our addresses with third parties we've never heard of?