Asos confirms breach of customer data after hackers send rogue app notification
First reported by TechCrunch ·
Your personal and contact information, including your home address and search history, may be exposed if you are an Asos customer.
Fashion retail giant Asos has confirmed a data breach affecting its customers' personal information after a third-party platform, used for customer communications and data analysis, was compromised. Hackers gained access to names, contact details, home addresses, phone numbers, and email addresses. The attackers exploited the breach by using Asos's own app notification system to inform customers that the company's data had been compromised, threatening to leak the information unless Asos engaged with them. The breach reportedly occurred through the impersonation of a trusted contact to obtain login credentials for the platform, which is a Snowflake instance. It remains unclear if this specific instance was protected by multi-factor authentication or how access to the in-app notification service was obtained. The group behind the attack, known as Xuanye Group, has not disclosed the amount of data they possess. Asos has approximately 17 million customers globally.
The intrusion method, involving impersonation to acquire credentials for a third-party platform, highlights a prevalent attack vector targeting vendor relationships. This suggests that the security of a company's data is only as strong as its weakest third-party link, prompting a re-evaluation of vendor risk management practices across the retail sector. The use of the company's own app to broadcast the breach and exert pressure is a novel and aggressive tactic that could signal a shift in cyber extortion methodologies.
This incident underscores the critical need for robust security measures, including multi-factor authentication, across all platforms handling sensitive customer data, especially those integrated with customer-facing applications. The potential for attackers to leverage legitimate communication channels for their own ends necessitates enhanced monitoring and incident response protocols for companies relying on such services. Businesses should anticipate increased scrutiny on their data handling practices and the security postures of their technology providers.
AI-written summary. May contain errors.