HomeMalware & ThreatsAttackers Take Over Asos App to Announce Store Hacked

Attackers Take Over Asos App to Announce Store Hacked

Published on

spot_img

Cybercrime,
Fraud Management & Cybercrime,
Incident & Breach Response

Asos Lost Control of its Story to ‘Advanced Persistent Teenagers’

Attackers Take Over Asos App to Announce Store Hacked
Image: Shutterstock

The popular fast-fashion online retailer Asos experienced a significant security breach recently, raising concerns among its users about the safety of their personal information. On a Tuesday morning, customers received an alarming notification through the store’s app, reportedly initiated by the hackers who gained unauthorized access to the British company’s systems. This notification stated unequivocally, “ASOS HACKED.” Reports from users spanned several countries, including the United Kingdom, France, Ireland, Sweden, and Australia.

The message conveyed a stark ultimatum, reading: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance.” The hackers demanded that the data protection officer and the IT department engage with them or face the potential leakage of sensitive customer data. The attackers left a link directing to a Telegram channel, ominously named “Xuanye group,” where they continued their extortion activities.

In the wake of the breach, Asos publicly announced that it is currently investigating the matter. The London-based retailer serves a vast customer base, boasting around 17 million active users across more than 150 countries. It operates shipping centers situated in England, Berlin, and Dallas.

As the severity of the situation unfolded, Asos faced mounting pressure from both the public and media. However, the company did not initially respond immediately to the deluge of news coverage. The hackers, meanwhile, attempted to mitigate panic by asserting that customers’ payment information remained safe. They followed up with a “final statement” claiming that while customer information had indeed been accessed, it would not be touched for a defined period.

Ultimately, Asos confirmed it was investigating the incident. A company spokesperson stated, “We are investigating unauthorized activity involving third-party platforms that we use to communicate with customers.” They added that immediate measures had been taken to limit access to these notification platforms while collaborating with both internal and external cybersecurity specialists and relevant authorities. In their disclosure, Asos indicated that basic personal information, such as names and contact details, could have been accessed, though they reassured customers that credit card information or account passwords were not believed to be compromised. Furthermore, the company noted that it retains cybersecurity insurance through a prominent global provider. However, by the time this information was made public, Asos’s stock price had already plummeted by 13%.

No Proof of Customer Data Theft

Asos customers have been advised to remain vigilant regarding the potential misuse of their personal details for fraudulent activities. The UK’s National Cyber Security Center issued a cautionary note, stating that customers should assume involvement in the incident, irrespective of whether they received the unauthorized notification directly.

The cloud-based data warehousing platform Snowflake is currently conducting its own investigation into the claims made by the attackers but, as of now, has found no substantiation for the breach claims. Experts surmise that the attackers’ assertion about breaching Snowflake could be misleading, potentially alluding to a prior incident involving numerous Snowflake customers that occurred in 2024.

According to cybersecurity professionals, the ability of the attackers to send notifications to users indicates access to a customer messaging channel rather than possession of a full customer database. Anastasia Tikhonova, global head of threat research for Group-IB, remarked, “The statement from Xuanye that it holds customer data on its server remains unverified.” She underscored that, to date, no concrete evidence has emerged confirming the breach or the nature of the accessed data.

Crisis Communications

The situation also highlights elements of crisis communication strategy employed by the attackers; their tactic was notably effective in promptly broadcasting their extortion demands to affected customers. Group-IB pointed out that the hackers’ approach to using a customer-facing notification channel underscores a new, direct strategy in extorting companies. By thrusting their message into public view, they successfully escalated pressure on Asos before the technical aspects of the breach were clearly understood.

Crisis communication experts suggest that defenders need to distinguish between the claims made by attackers and what can be reliably verified. “Fake notifications are nothing new,” commented Ian Thornton-Trump, Chief Information Security Officer of cybersecurity firm Inversion6. He emphasized that this incident underscores the necessity for companies to have a robust response strategy against young and agile cyber extortion groups. “Being prepared involves having a comprehensive playbook,” he asserted. He advised that organizations should proactively flood the media space with messaging to reassure customers and maintain trust, rather than delaying communications due to legal deliberations.

The incident surrounding Asos serves as a cautionary tale for the fast-fashion retail industry and highlights the ever-evolving threats posed by cybercriminals. It is critical for companies to remain vigilant and ready to engage with customers transparently in order to navigate the tumultuous waters of modern cybersecurity challenges.

Source link

Latest articles

Telegram Account Linking ASOS Rogue Notification to Gaming Trading

ASOS Breach Investigation: Insights from Group-IB and Industry Experts Recent revelations from Group-IB, shared exclusively...

Power BI Phishing Campaign Distributes Malicious ScreenConnect Clients

Attackers Exploit Microsoft Power BI for Phishing Campaign Recent research from Huntress has revealed alarming...

Encrypted Instructions Manipulate Copilot CLI to Reveal Developer Secrets

New Security Vulnerability Discovered in GitHub Copilot CLI: Sensitive Data at Risk Recent studies conducted...

Cyber Briefing – October 7, 2026: CyberMaterial

FortiBleed Campaign: Ongoing Threats in Cybersecurity In the realm of cybersecurity, the FortiBleed campaign remains...

More like this

Telegram Account Linking ASOS Rogue Notification to Gaming Trading

ASOS Breach Investigation: Insights from Group-IB and Industry Experts Recent revelations from Group-IB, shared exclusively...

Power BI Phishing Campaign Distributes Malicious ScreenConnect Clients

Attackers Exploit Microsoft Power BI for Phishing Campaign Recent research from Huntress has revealed alarming...

Encrypted Instructions Manipulate Copilot CLI to Reveal Developer Secrets

New Security Vulnerability Discovered in GitHub Copilot CLI: Sensitive Data at Risk Recent studies conducted...