Asos app delivers a data leak threat instead of fast fashion

Asos app delivers a data leak threat instead of fast fashion

Asos customers have reported receiving a rogue app notification claiming the online clothing retailer’s Snowflake instance has been compromised and threatening to leak data. The notification included a link to a Telegram channel named “Xuanye Wen Gateway” and addressed Asos’s data protection officer and IT team. “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” it says. The notification does not, by itself, establish that the sender accessed Asos’s Snowflake instance or sensitive customer data. How the message was sent remains unclear. Asos’s share price fell by around 12 percent following reports of the notification, although it has recovered slightly since. Several hours after publication, an Asos spokesperson confirmed the attack and claimed it had limited impact, telling The Register, “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted. Our website and app are operating as normal, with no current disruption to any aspects of our operations.” The spox added, “The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.” Snowflake did not immediately return a request for comment. Customers of Snowflake, a cloud platform for storing and analyzing data, were targeted in a major data theft campaign in 2024, including Ticketmaster, Santander, AT&T, and dozens of others. Connor Riley Moucka, 26, of Kitchener, Ontario, later pleaded guilty to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over a hacking spree that compromised more than 165 organizations, exposed billions of customer records, and brought in about $2.5 million in ransom payments. Snowflake subsequently introduced controls allowing administrators to require multi-factor authentication. ® Updated Oct 6 at 1742 GMT to add Asos’ confirmation of the attack and comment.

By jawad