The attackers sent a push notification to Asos shoppers announcing their activity.
UK-based fashion retailer Asos is doing damage control after its customers were sent a push notification claiming that its cloud services had been hacked. According to The Guardian, Asos users received mobile alerts that were addressed to the company’s data protection officer and IT personnel.
The notifications read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it.” Snowflake is a cloud service that handles push notifications as well as managing data about transactions and customer demographics. A link in the message sent users to a Telegram channel claiming to be operated by Xuanye Group, a reportedly unknown name among most cybersecurity circles.
According to the company’s statement, “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
Asos said that although customers’ names and contact information may have been accessed in the hack, it did not believe payment details or passwords had been compromised. The company added that its app and website were operating as usual.
