—
00:00
Tech and Rich
Tech and Rich
USD/RUB—
EUR/RUB—
Startups & Technology

Asos Customer Data Exposed via Third-Party Breach

Hackers have infiltrated a third-party platform used by Asos, gaining access to customer names, home addresses, phone numbers, and search histories. The attackers signaled their intrusion by hijacking the retailer’s own mobile application to send an unauthorized notification, effectively holding the internal data hostage to force a ransom negotiation.

Asos Customer Data Exposed via Third-Party Breach

The security lapse involves a Snowflake instance used by the fashion giant to analyze corporate data. According to the Xuanye Group, the collective behind the breach, the intrusion occurred after they impersonated a trusted contact to harvest login credentials. While Snowflake maintains its core infrastructure remains secure, the incident highlights a growing trend of attackers leveraging third-party communication tools to exert pressure on corporate targets.

Asos confirmed the incident in a filing with the London Stock Exchange, noting that the compromised information includes sensitive profile notes and contact details. By weaponizing the company’s push notification system, the perpetrators are attempting to bypass traditional communication channels to demand engagement. This strategy mirrors recent tactics seen at firms like Betterment, where attackers similarly compromised third-party marketing platforms to deliver malicious content directly to users. Asos currently serves approximately 17 million customers, though the full scale of the data exfiltration remains unverified.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!