Uk.Finance.Yahoo Asos Cyber Breach Linked to Employee Credential Theft
Article Content
- •Asos was hacked via employee credential theft, not a Snowflake vulnerability.
- •No sensitive payment information was compromised in the breach.
- •Asos and Snowflake are actively communicating with customers regarding safety measures.
Asos reported a cybersecurity breach where an unauthorized party accessed an employee account by impersonating a trusted source to obtain login credentials. The attacker claimed to have compromised the Snowflake instance used by Asos, but Snowflake confirmed that the breach was not due to any vulnerability in its platform. Asos stated that no payment card information or account passwords were accessed, and the website and app remain safe to use. Customers were alerted about the breach via phone notifications, and Asos has advised them to be cautious of unsolicited communications. The incident is under investigation, and no remediation is required for Snowflake customers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ASOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was compromised?
How did the breach occur?
What should Asos customers do?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…