UK fashion retailer Asos has confirmed that hackers accessed customers’ personal information after compromising a third-party platform used by the company to communicate with its users. The attackers then used Asos’ own app notification system to alert customers that the company had been breached.

Asos disclosed the incident in a filing with the London Stock Exchange, stating that attackers gained access to a third-party platform hosting data used for customer communications.

The company confirmed that names and contact details were among the information taken during the breach.

The compromised data reportedly includes customers’ home addresses, phone numbers and email addresses, along with notes connected to customer profiles, including records of searches carried out on the Asos website.

Asos said the hackers issued an “unauthorised customer notification”, which was subsequently shared by several users on social media. The message was directed at Asos’ data protection officer and IT department and claimed that the attackers had “fully compromised” the company’s data hosted on Snowflake. The message also threatened: “Engage with us, or we will leak it.”

Using Asos’ own in-app notification system to contact customers appears to be an attempt to pressure the company into engaging with the attackers, with the threat of publishing the stolen information online if it refuses.

The attackers reportedly gained access to the Snowflake environment by “impersonating a trusted contact to obtain log in credentials”. Snowflake has said that it did not suffer a breach of its own systems. It remains unclear whether Asos’ Snowflake environment was protected by multi-factor authentication, while the method used to gain access to the system responsible for sending in-app push notifications has also not been established.

The attackers, operating under the name Xuanye Group, have not disclosed how much Asos data they claim to have obtained. Asos says its business has around 17 million customers.

The incident follows another breach earlier this year involving fintech company Betterment, where hackers exploited access to a third-party marketing platform to impersonate the company and send customers a fraudulent cryptocurrency notification. That attack also exposed customer information including names, email addresses and phone numbers, among other data.

LEAVE A REPLY

Please enter your comment!
Please enter your name here