Hackers hijack ASOS app to send customers a "HACKED" extortion notification

· CyberSecurity

TLDR

  • UK fashion retailer ASOS confirmed a data breach after hackers sent an unauthorised "ASOS HACKED" push notification to app users on Tuesday.
  • A group calling itself "Xuanye" claimed in the notification and on Telegram to have fully compromised ASOS's Snowflake data environment and threatened to leak stolen data.
  • ASOS has not confirmed the Snowflake claim or disclosed how many customers are affected, but says basic personal information such as names and contact details may have been exposed.
  • Shares in the company fell around 10% on Tuesday; the breach also reached app users in Australia, France, Sweden and Ireland.

The notifications began appearing on ASOS app users' phones at around 5:00 a.m. ET (10:00 BST) on Tuesday, addressed to the company's data protection officer and IT team: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."1 The message linked to a Telegram channel run by the self-described "Xuanye group," which later posted a "FINAL STATEMENT" claiming it held stolen customer information "safe on our server" and would not touch it "for a designated period."1 The group did not disclose what data it took, how many customers were affected, or provide evidence that it had actually breached ASOS's Snowflake environment.1

ASOS acknowledged "unauthorised activity involving third-party platforms" and said some "basic personal information," including names and contact details, may have been accessed; the company says it does not believe payment-card information or account passwords were affected and has not yet notified the UK's Information Commissioner's Office.2 Cyber-security experts described the tactic as unusually aggressive. Charlotte Wilson, head of enterprise at Check Point, called it "deeply serious" and "brazen," saying the hackers had "turned Asos' own app into their ransom note," while adding that customers should not be "scared and frightened" but should change their passwords and watch for follow-on phishing.2

ASOS serves around 17 million customers a year across more than 150 markets, and its app has been downloaded more than 10 million times on Android alone; the notification also reached some users in Australia, France, Sweden and Ireland.2 Shares in the company fell by around 10% on Tuesday.2

Why it matters: turning a retailer's own app into the extortion message, rather than emailing the company privately, is a rare and deliberately public pressure tactic, and the unverified Snowflake claim echoes a wave of attacks on companies' Snowflake cloud-data environments that has hit numerous retailers over the past two years.

Sources

  1. ASOS confirms data breach after "HACKED" in-app notifications (BleepingComputer)
  2. 'ASOS hacked': App users receive notifications sent by hackers (BBC)