British fashion retail giant Asos confirms a breach of customer personal information. Previously, hackers used the company's app to send notifications to users, claiming that the company had been compromised.
Asos stated in a document submitted to the London Stock Exchange that hackers gained access to a third-party platform that hosts data, which the company uses to communicate with its clients.
The company stated that the information that was compromised in the leak included names and contact details.
BBC News reports that the stolen data also includes home addresses, phone numbers, and email addresses, as well as notes related to customer information, such as their search queries on the website.
Asos indicates that hackers sent an "unauthorized customer notification," which many people posted on social media. The notification was addressed to Asos's data protection officer and the IT department, claiming that hackers had "completely breached" the data hosted by the company on Snowflake. Snowflake is a technology company that allows corporate clients to analyze large amounts of data. The notification stated, "Contact us, otherwise we will disclose it."
Hackers issue warnings to customers through their own notification systems, attempting to force the company to contact them, otherwise they may release the stolen data online.
According to Bleeping Computer, these hackers are said to have gained access to the Snowflake instance by "pretending to be trusted contacts to obtain login credentials." Snowflake stated that its system itself was not compromised. It is still unclear whether the Snowflake instances operated by Asos had multi-factor authentication enabled. It is also not clear how the hackers obtained system access rights to Asos used for sending in-app push notifications, as such functionality is usually handled by third-party services.
These hackers, who claim to be Xuanye Group, have not yet stated how much data they claim to have in their possession. The Asos website indicates that the company has 17 million customers.
Earlier this year, the fintech giant Betterment also suffered a hacker attack. The hackers took advantage of their access to the company's third-party marketing platform to impersonate the company and send cryptocurrency scam messages to customers. During this attack, the hackers also obtained data such as customer names, email addresses, and phone numbers.












