Hackers hijack ASOS app alerts after stealing customer data

Published

On the morning of Tuesday, October 6, ASOS customers opened their phones to a notification from the fashion retailer's own app that read like a ransom note. Addressed to the company's data protection officer and IT team, it claimed the attackers had "fully compromised" ASOS's Snowflake instance and told the retailer to engage with them or see the data leaked.

It was not a hoax. ASOS confirmed an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms it uses to communicate with customers. The UK's National Cyber Security Centre issued an alert for ASOS customers the same day, advising anyone with an account to assume they are affected even if they did not receive the message.

One phished login, several platforms

ASOS has since said the attackers obtained customer information after tricking an employee into handing over login credentials, then used those credentials to reach third-party platforms the retailer relies on. The company says it locked down the affected platforms, brought in internal and external specialists and strengthened its security controls.

The attackers named Snowflake, the cloud data platform, in their message. According to Malwarebytes' follow-up, they later said they got in through Simon AI, a customer personalization service built on Snowflake that ASOS uses for marketing. Snowflake says it found no compromise of its platform. Logging into a customer's connected service with a stolen password is not the same as breaching the platform underneath, and nothing published so far points to a vulnerability in either product. The account-takeover pattern is familiar from the wave of Snowflake customer breaches, where stolen logins rather than software flaws did the damage.

More than names and email addresses

ASOS initially said "basic personal information including name and contact details" may have been accessed, and that it does not believe payment card details or account passwords were affected. Malwarebytes reports that a data sample the attackers circulated goes further, including home addresses, phone numbers, dates of birth, customer numbers, when a customer started shopping with ASOS, and searches they ran on the site. The group, which Malwarebytes reports calls itself Xuanye, is said to have given ASOS two weeks to make contact and to be demanding a ransom to delete the data. ASOS has not said whether it will pay.

Rapid7's Emma Burdett points out why the delivery route matters. Most anti-phishing advice teaches people to spot an odd sender or a wrong domain, and none of that helps when the message arrives through a genuine app already on the phone. Every SaaS tool that can speak to customers in a company's name is part of its attack surface.

Ignore the Telegram link and expect scams

The immediate risk for customers is follow-on fraud. A message that knows a shopper's name, address and recent searches will look convincing, especially one offering a refund, delivery fix or "security check" tied to the breach. Do not follow the Telegram link in the attackers' notification, go to the ASOS website or app directly rather than through links in messages, and never share passwords, one-time codes or card details in response to an unsolicited contact. ASOS says it will contact affected customers directly where further action is needed, and the NCSC's data breach guidance covers the rest.

For businesses, the lesson is uncomfortable. The weakest point here was not a database but a person and the trust customers place in a push notification, and both can be borrowed by anyone holding the right password.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions