Hackers breach Asos customer data, then taunt the company through its own app

Asos confirmed on October 8 that attackers breached customer personal data, in a disclosure filed with the London Stock Exchange. The UK fashion retailer, which lists 17 million customers on its website, said names and contact information were taken, though it hasn't disclosed how many accounts were affected.
According to BBC News, the stolen data extends beyond basic contact details to home addresses, phone numbers, and notes attached to customer profiles, including website search queries — the kind of behavioral data that makes a breach more useful to scammers running targeted phishing than a simple name-and-email leak.
How the attackers got in
Bleeping Computer reports the attackers compromised Asos's Snowflake instance, the cloud data platform the retailer uses to host customer data for communication purposes, by impersonating a trusted contact to obtain login credentials. Snowflake has said its own systems were not breached, placing the failure on the credential theft rather than a platform-level vulnerability — the same pattern behind last year's wave of Snowflake-linked breaches at other major retailers. Whether the compromised account was protected by multi-factor authentication hasn't been disclosed.
Extortion through the company's own app
The attackers, who identify themselves as Xuanye Group, didn't stop at stealing the data. They sent an unauthorized push notification through Asos's own app, addressed to the company's data protection officer and IT department, claiming to have "fully compromised" its Snowflake data and warning: "Engage with us, or we will leak it." Customers who received the notification posted it widely on social media, turning what might have been a quiet extortion attempt into a public one. How the attackers gained access to the app's push notification system — typically operated by a third-party service separate from the core data platform — hasn't been explained.
Part of a pattern
The Snowflake-credential-theft method mirrors an attack earlier this year on fintech firm Betterment, where hackers used a compromised third-party marketing platform to impersonate the company and send a crypto scam message to customers, after accessing names, emails, and phone numbers. The repetition points to the same underlying weakness across retailers and financial firms: data platforms secured well at the infrastructure level but exposed through credential theft and loosely governed third-party integrations that can send messages on a company's behalf.
Asos has not said whether it will pay the attackers' demand, and has not confirmed the scale of the breach beyond acknowledging that names and contact data were exposed. The company's response in the coming days — particularly whether it negotiates or stays silent — will likely determine whether Xuanye Group follows through on its threat to publish the stolen data.
Originally reported by TechCrunch. Read the original article for additional details.
View original source