ASOS Users Targeted by Unauthorized App Notifications

UK-based ASOS customers were greeted Tuesday morning by alarming in-app notifications claiming the retailer’s data infrastructure had been compromised. The messages, purportedly from a group calling itself the Xuanye Group, warned of a breach involving a Snowflake instance, prompting immediate concerns over the security of personal user data.

Yesterday, 20:04
1,925 0
ASOS Users Targeted by Unauthorized App Notifications

Snowflake serves as a cloud-based data platform where corporations store and analyze vast quantities of information. Think of it as a rented, highly organized warehouse: the company dictates what data enters and who holds the keys, while Snowflake manages the underlying architecture. An 'instance' effectively functions as a private, isolated environment within that warehouse, equipped with its own unique access controls and user credentials.

While the hackers claim to have breached this specific environment, ASOS has not confirmed the use of Snowflake services, and the company remains absent from Snowflake's published partner list. In an official statement via Instagram, ASOS characterized the incident as an unauthorized push notification rather than a full-scale system compromise. The retailer acknowledged that names and contact details may have been accessed, though it maintains that passwords and payment information remain secure.

ASOS has restricted access to the affected systems and is currently working with internal and external security specialists alongside relevant authorities. The company strongly advises users to ignore the pop-up messages and refrain from clicking any links, which currently redirect to a Telegram channel. Although management asserts that account credentials were not compromised, updating passwords remains a prudent step for users who reuse login information across multiple platforms.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!