Technology2 min read

Asos confirms breach of customer data after hackers send rogue app notification

By · Published by Everything Blog

In short

Asos confirms a data breach after hackers exploited a rogue app to steal customer information and send unauthorized notifications. The breach involved stolen names and contact details, and the hackers urged Asos to engage with them or risk having the data published online. The incident underscores the importance of securing third-party platforms and robust data protection measures.

Key points

  • Hackers used a rogue app to steal customer information.: Hackers used a rogue app to steal customer information.
  • The breach involved stolen names and contact details.: The breach involved stolen names and contact details.
  • The hackers urged Asos to engage with them or risk having the data published online.: The hackers urged Asos to engage with them or risk having the data published online.

UK fashion retail giant Asos has confirmed a data breach of its customers’ personal information after hackers used the company’s own app to notify users that the company had been compromised.

Asos said in a filing with the London Stock Exchange that hackers broke into a third-party platform hosting data that the company uses to communicate with customers.

The company said that names and contact information were taken in the breach.

BBC News reports that the stolen data includes home addresses, phone numbers, and email addresses, as well as notes relating to customer profiles, such as their website search queries.

Asos said the hackers sent an “unauthorised customer notification,” which many posted to social media. The notification addressed Asos’ data protection officer and IT department and said that the hackers “fully compromised” the company’s data hosted on Snowflake, a tech company that allows its corporate customers to analyze large amounts of data. “Engage with us, or we will leak it,” the notification reads.

By using the app’s own notification system to alert customers, the hackers are trying to pressure the company into engaging with them or risk having the stolen data published online.

The hackers reportedly broke into the Snowflake instance by “impersonating a trusted contact to obtain log in credentials,” reports Bleeping Computer. Snowflake said it had not experienced a breach of its systems. It’s unclear if the Asos-run Snowflake instance was protected with multi-factor authentication. It’s also not known how the hackers gained access to Asos’ system for sending in-app push notifications, which is often handled by a third-party service.

The hackers, who go by the handle Xuanye Group, have not indicated how much data they allegedly possess. Asos has 17 million customers, according to its website.

Earlier this year, fintech giant Betterment was compromised by hackers who used their access to the company’s third-party marketing platform to impersonate the company and send a crypto scam to its customers. The hackers also access customer names, email addresses, and phone numbers, among other data, during the breach.

Original source: techcrunch.com

Technology