Asos confirms breach of customer data after hackers send rogue app notification
Hackers accessed customer personal information via a third-party platform and used the Asos app to issue ransom demands.
Quick Look
- UK retailer Asos confirmed a data breach involving customer names, addresses, and contact details.
- Hackers, identifying as Xuanye Group, compromised a third-party data platform and used the Asos app's notification system to demand engagement under threat of data leakage.
AI-generated summary
Why It Matters
Asos uses third-party platforms to manage customer communications and data analysis. The breach involved unauthorized access to a Snowflake instance used by the retailer.
UK fashion retail giant Asos has confirmed a data breach of its customers’ personal information after hackers used the company’s own app to notify users that the company had been compromised.
Asos said in a filing with the London Stock Exchange that hackers broke into a third-party platform hosting data that the company uses to communicate with customers.
The company said that names and contact information were taken in the breach.
BBC News reports that the stolen data includes home addresses, phone numbers, and email addresses, as well as notes relating to customer profiles, such as their website search queries.
Asos said the hackers sent an “unauthorised customer notification,” which many posted to social media. The notification addressed Asos’ data protection officer and IT department and said that the hackers “fully compromised” the company’s data hosted on Snowflake, a tech company that allows its corporate customers to analyze large amounts of data. “Engage with us, or we will leak it,” the notification reads.
By using the app’s own notification system to alert customers, the hackers are trying to pressure the company into engaging with them or risk having the stolen data published online.
The hackers reportedly broke into the Snowflake instance by “impersonating a trusted contact to obtain log in credentials,” reports Bleeping Computer. Snowflake said it had not experienced a breach of its systems. It’s unclear if the Asos-run Snowflake instance was protected with multi-factor authentication. It’s also not known how the hackers gained access to Asos’ system for sending in-app push notifications, which is often handled by a third-party service.
The hackers, who go by the handle Xuanye Group, have not indicated how much data they allegedly possess. Asos has 17 million customers, according to its website.
Open Questions
- Was multi-factor authentication enabled on the Snowflake instance?
- How did hackers gain access to the in-app push notification system?







