ASOS Hacked: Customers Sent App Alert

“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” the message reads.
“If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note,” says Charlotte Wilson, head of enterprise at cyber-security firm Check Point. “Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company.”
On social media, dozens of people have posted about receiving the message, confused about what it means.
The BBC reports that although the apparent extortion message was sent directly to customers, it is addressed to ASOS’ data protection officer (DPO) and IT team.
The message claims the unnamed hackers have “fully compromised the Snowflake instance”. This refers to the data storage company Snowflake, whose tools are used by dozens of firms to collect, analyse, and store data.
It is not known whether ASOS is a Snowflake customer or what data, if any, is stored with the service.
But Snowflake has been the subject of many high-profile data breaches in recent years and has been linked to incidents targeting services including Ticketmaster and Santander.
It is, however, very unusual for a data breach to be revealed quite so publicly – and for customers to be informed in this manner.
Most extortion and negotiations by cyber criminals are conducted in private, with hackers hoping discretion will lead to a quiet payoff.
The pop-up message contains a link to the hackers’ Telegram channel.
The new group calls itself Xuanye Group and created its Telegram channel only today. They have posted only three times, with the latest being about the ASOS hack.
Dan Bird, from cybersecurity firm HHorizon33, says the pop-up message the criminals sent implies that their access has gone beyond the Snowflake database.
“Sending a push notification to ASOS’s app users would require access to the company’s notification system, which is separate from the Snowflake data platform the attackers claim to have compromised. If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door,” he said.