ASOS said it was investigating after mobile app customers reported receiving notifications which claimed hackers had “compromised” the online fashion retailer’s systems and breached shopper data.

App users were sent push messages from suspected hackers, which were addressed to the retailer’s Data Protection Office (DPO) and threatened to leak shoppers’ data. It is understood the messages also referred to cloud platform, Snowflake, which the alleged hackers said was “fully compromised.”

The pop up message also contained a link to the hackers’ Telegram channel, owned by a new cybercrime collective calling itself Xuanye Group.

“In this instance, hackers are claiming to have gained access to ASOS’s Snowflake cloud database, and are using customer app notifications to cause heightened panic as a form of extortion and blackmail,” explained Nick Dyer, a cybersecurity expert from Arctic Wolf.

However, Horizon3’s security expert, Dan Bird, warned that the nature of the message sent by the hackers implies their access may have gone beyond the Snowflake database.

“Sending a push notification to ASOS’s app users would require access to the company’s notification system, which is separate from the Snowflake data platform… which suggests the attackers got hold of credentials that opened more than one door,” he said.

According to a Senior Information Security Researcher at Cybernews, Aras Nazarovas, openly threatening victims is a fairly common tactic, with hackers hoping to “put psychological pressure on decision-makers” by publicly announcing the breach.

“Depending on what was stored, this could include customer, sales, order, marketing or operational datasets… While we don’t know if users have been compromised, ASOS has around 17million customers globally, meaning the scale of this breach could be significant,” Dyer added.

Leave a comment

Trending