Back Bankinfosecurity Attackers Hijack Asos App to Say Store is Hacked
Fanciers of fast-fashion online retailer Asos received an unusual notification from the store app Tuesday, apparently sent by the hackers who hacked the British company.
See Also: Scattered Spider Exposed: Critical Takeaways for Cyber Defenders
"ASOS HACKED" popped up on the app mid-morning, according to multiple users across the United Kingdom, as well as users in France, Ireland, Sweden and Australia.
"Dear Asos DPO and IT, we have fully compromised the Snowflake instance," the pop-up message read, demanding that the data protection officer and IT department "engage with us, or we will leak it." It was signed with a link to social platform Telegram that resolved to a channel titled "Xuanye group."
Asos said it's investigating. The London company counts 17 million active customers in more than 150 countries, and runs shipping centers in England, Berlin and Dallas.
As the breach unfolded on Tuesday morning, triggering live news coverage, the company didn't immediately .
In the hours-long interim, Xuanye group posted Tuesday morning that "regarding ASOS, payment information is not affected." A "final statement" from the extortionists followed in the afternoon, stating: "The affected organizations app is safe to use. The incident involves customer information, it is safe on our server, and it will not be touched for a designated period."
Later that day, Asos confirmed it is probing the incident. "We are investigating unauthorized activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities," Asos said .
"Basic personal information including name and details may have been accessed. We do not believe that payment-card information or account passwords, were impacted," it said. The company disclosed that it has "cybersecurity insurance with a large global provider."
No Proof of Customer Data Theft
All Asos customers should beware the potential use of their personal details for fraudulent purposes. "If you are an Asos customer, you should assume you are affected by this incident, even if you did not receive the unauthorized notification," said Britain's National Cyber Security Center.
Cloud-based data warehousing platform Snowflake said it's investigating the threat actor's breach claims but so far found nothing to substantiate it.
Attackers' Snowflake breach claim could be a red herring, perhaps meant to imply some connection to a prior breach of numerous Snowflake customers' accounts in 2024 perpetrated by cyber extortion collective ShinyHunters.
"Being able to send a notification shows access to a customer-messaging channel, not possession of a customer database," said Anastasia Tikhonova, global head of threat research for cybersecurity firm Group-IB. In addition, "Xuanye's statement that it holds customer data on its server is unverified. We have seen no sample, dump or other evidence," she said.
Little is known the threat actor. Its Telegram channel was only created Tuesday. "The Telegram account now behind it carried other names earlier, largely in gaming-item trading. That suggests an identity set up or reorganized around this incident. It does not tell us who controls it, how experienced they are or how access was gained and we have no evidence on the entry route," Tikhonova said.
Crisis Communications
Whatever the extortionists may have stolen or accessed, one notable facet to their attack was their ability to quickly make their shakedown message widely seen. "The notable tactic here is the use of a customer-facing notification channel to push the extortion attempt directly in front of users, then move the conversation to Telegram. That creates pressure before the technical picture is clear," Group-IB said in a post to social platform X.
"For defenders, the key is to separate actor claims from what can actually be verified, especially around data theft, access and attribution," it said.
Extortionists regularly seek strategies that add pressure on victims to pay. "Fake notifications are nothing new, this was only novel in the idea that it engaged the customers directly to help with the data extortion demand - to, as we say, maximize the pain and payout," Ian Thornton-Trump, CISO of cybersecurity firm Inversion6, told ISMG.
Attackers' messaging enabled them to control the narrative for a period of hours. "The extortion group's push message has caused BBC News to clear the air waves for it, set up a dedicated YouTube stream for it and the company has no media statement," said British cybersecurity expert Kevin Beaumont in a post to social platform Mastodon, as the incident unfolded.
One immediate cybersecurity takeaway from the Asos incident, he said, is this: "Have a playbook for Advanced Persistent Teenagers, ransomware and extortion groups. Practice it."
"You need to flood the zone with messaging, put it on the front page of your website, be calm and upfront with customers. If you have 15 lawyers on a call debating legal risks, you'll lose customer trust. Get the CEO on BBC News," he said.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
