British online retailer ASOS has verified that a cyberattack has compromised a third-party communication platform, resulting in unauthorized notifications sent to users’ devices.
Unauthorized Notifications Trigger Concerns
Recently, many ASOS users in the UK reported receiving unexpected notifications on their mobile apps. One such notification was labeled ‘ASOS hacked’ and contained a message directed at ASOS’s data protection officer and IT team, stating that a Snowflake instance had been compromised.
ASOS, in a statement to the London Stock Exchange on Tuesday, acknowledged the breach. The retailer confirmed that these unauthorized notifications were a result of a hack on a third-party platform used for customer communications.
ASOS Takes Immediate Action
The company has responded swiftly by limiting access to the affected notification platforms. ASOS is collaborating with internal and external cybersecurity experts, alongside relevant authorities, to address the situation.
ASOS disclosed that while basic user information, such as names and contact details, might have been accessed, they do not believe that payment card details or account passwords were compromised. Additionally, the company reassured that its main website and application remain secure and operational.
Speculation Around the Attack
While ASOS has not revealed which specific platform was breached, speculation points to the involvement of Snowflake, a data analysis and AI platform. In the past, similar breaches involved stealing credentials through infostealers, as noted by Daniel dos Santos from Forescout Research – Vedere Labs.
The hacking group, Xuanye Group, claimed responsibility for the breach on a newly established Telegram channel. Though the name suggests a Chinese-speaking group, it may also be a deceptive tactic.
According to Natalie Page from Talion Cyber Security, the method of directly messaging customers signifies an attempt by the attackers to gain visibility. This strategy is common among extortion groups aiming to pressure companies by leveraging media exposure.
The situation remains under investigation, with experts emphasizing the need to understand the vulnerabilities exploited during the attack to prevent similar incidents in other organizations using similar platforms.
