British clothing retailer Asos on Tuesday evening confirmed it is investigating “unauthorised activity” involving third-party platforms that it uses to communicate with customers, after people in multiple countries received a notification from the Asos smartphone app that was apparently sent by a hacking group.
The notification, sent on Tuesday morning, was headlined “Asos Hacked” and was addressed to the company’s data protection officer and IT team, informing them that a Snowflake data-analysis instance had been compromised and would be leaked unless the company “engaged” with the attackers.
The message provided a link to a newly created Telegram channel that identified the hackers as Xuanye Group, a previously unknown threat entity.
Extortion
Snowflake, which provides tools companies use to collect, analyse and store customer data, said it was investigating but had so far found no compromise of its platform.
The company has in the past been linked to major breaches of customer data, including incidents involving Ticketmaster and Santander.
The use of a notification involving the Asos app appears to indicate a separate compromise of Asos’ notification system, security experts said.
The notification, which local reports indicated had been sent to users in Australia, France, Sweden and the Republic of Ireland, appeared to be an extortion tactic to encourage Asos to meet the attackers’ demands, likely a ransom paid not to release compromised Snowflake data.
Asos said it is working with specialists and advisors to investigate, and that its website and app are operating as normal.
Social engineering
It said basic information such as names and contact details may have been accessed, but it did not believe payment card records or passwords had been affected.
Security experts urged customers to beware of other attackers using the incident to carry out attacks.
“Other attackers will likely jump on the incident to send out malicious communications, so customers of Asos should be aware of this social engineering tactic,” Natalie Page, head of threat intelligence at Talion, told Silicon UK.
Previous Snowflake breaches have been linked to loose-knit gangs variously referred to as UNC5537, ShinyHunters or Scattered Spider, members of which are currently being hunted by US authorities after stealing extensive data on FBI employees via a compromised Oracle PeopleSoft database.
Click Here For The Original Source.
