Users of the ASOS app in the UK have reported receiving unexpected pop-up messages that appear to be from hackers attempting to extort the company. Multiple individuals have shared experiences of receiving unusual notifications that show up on their mobile devices, signaling a significant security concern for ASOS.
The message displayed on users' screens states, "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." Despite efforts to reach out to ASOS for clarification, the company has not yet responded.
Charlotte Wilson, the head of enterprise at a cyber-security firm, noted the severity of the situation, indicating that the hackers seem to have utilized ASOS's own app as a means to convey their ransom demand. This is alarming, as many individuals trust app notifications to come directly from the companies they use.
Details of the Hack
On various social media platforms, users have expressed confusion and concern over the message they received. Although the notification seems directed towards ASOS's internal teams, including the data protection officer and IT department, it has reached the customers directly. The hacking group claims to have completely compromised the Snowflake instance, a data storage service used by multiple companies to store and analyze information.
It remains unclear whether ASOS is indeed a client of Snowflake or if any sensitive data has been disclosed. Yet, Snowflake has faced scrutiny in previous data breaches tied to other major services.
David Bird, from another cyber security firm, commented that such public notifications of data breaches are rare. Typically, negotiations between cybercriminals and their targets tend to remain confidential, with hackers seeking to avoid interference in their efforts to secure payment.
The message also contains a link pointing to the hackers' Telegram channel, where they have identified themselves as the Xuanye Group, a newly created entity. Their activity shows only three posts as of now, with the latest being focused on the reported ASOS attack.
Access Implications
Experts further assert that issuing notifications via the ASOS app signifies that the attackers have potentially infiltrated systems beyond the mentioned Snowflake database. Since sending push notifications requires access to distinct company systems, it indicates that the hackers may have gained unauthorized credentials that provide access to multiple entry points within ASOS's operations.