Technology

ASOS Confirms Customer Data Theft After Hackers Hijack App Notification

Martin HollowayPublished 40m ago3 min readBased on 10 sources
Reading level
ASOS Confirms Customer Data Theft After Hackers Hijack App Notification
source:asosplc.com

ASOS confirmed on Oct. 8 that attackers stole customer personal data and then used its own app to tell customers about it.

The disclosure, reported by TechCrunch, followed two days of user reports about a rogue push notification. In a London Stock Exchange filing, ASOS said hackers broke into a third-party platform holding data ASOS uses to communicate with customers London Stock Exchange.

ASOS did not describe a breach of its main shopping system. It described compromise of a connected communications store, the type of system that keeps copies of customer records for messaging and personalization while sitting outside the strictest controls.

The data taken was names and contact information, according to the filing. That includes home addresses, phone numbers and email addresses, as well as notes tied to customer profiles such as website search queries. ASOS lists 17 million customers on its corporate site. The group behind the claim has not said how much ASOS data it allegedly holds.

The notification turned a quiet intrusion into a public incident. ASOS called it an "unauthorised customer notification" sent through its app. Recipients posted screenshots to social media. It was addressed to ASOS's data protection officer and IT department and said the hackers had "fully compromised" ASOS data hosted on Snowflake. It reads "Engage with us, or we will leak it." The hackers call themselves Xuanye Group.

How access was obtained matters more than where the data sat. The attackers got into the Snowflake storage area by impersonating a trusted contact to steal login credentials, according to BleepingComputer. Snowflake said it had not experienced a breach of its systems. This was theft of a password by tricking a person, known as social engineering, against one customer setup, not a flaw in the data platform itself.

The timeline moved quickly. App users raised the alarm about the rogue notifications before ASOS confirmed them. ASOS later confirmed its unauthorised notification was sent via its app on Tuesday, Oct. 6 BBC. Earlier that day the company said it was investigating unauthorised access to its app system after shoppers received notifications claiming its data was compromised.

Markets reacted before the full confirmation. ASOS shares fell after reports of the hack on Oct. 6, with one report putting the drop at 13% after the hacker push notification Reuters QZ.

The broader context here is the meeting of two patterns. In my view, customer messaging systems have become duplicate customer databases, copied from core records and rarely guarded with the same care. Push and in-app messages have also become a trusted channel that attackers can reuse for extortion, reaching victims directly without going through the press or a leak site.

In practical terms for teams running similar systems, the defensive questions are narrow. Which outside firms hold usable personal data, how long do they keep behavioral notes like search queries, how are logins for analytics copies issued and rotated, and who can send to the customer notification path. Compromise of any one of those turns a data theft case into a direct pressure campaign aimed at users.

Looking further ahead, better defenses already exist. Scoped credentials, short-lived tokens, phishing-resistant authentication for data platforms, and separate approval for broadcast messaging all exist. The ASOS case is a reminder that they need to cover messaging platforms and analytics copies, not only main databases.