Asos Confirms Customer Data Breach: Hackers Used Its Application to Send Abnormal Notifications
TechCrunch
1h ago
Ai Focus
Asos Confirms Personal Information Leakage of Customers. The company claims that hackers invaded their third-party platform used for communication with customers, stealing names, contact information, and other details; BBC states that the leaked data also includes home addresses, phone numbers, email addresses, and notes related to customer profiles.
Helpful
No.Help

British fashion retail giant Asos confirms a breach of customer personal information. Previously, hackers used the company's app to send notifications to users, claiming that the company had been compromised.

Asos stated in a document submitted to the London Stock Exchange that hackers gained access to a third-party platform that hosts data, which the company uses to communicate with its clients.

The company stated that the information that was compromised in the leak included names and contact details.

BBC News reports that the stolen data also includes home addresses, phone numbers, and email addresses, as well as notes related to customer information, such as their search queries on the website.

Asos indicates that hackers sent an "unauthorized customer notification," which many people posted on social media. The notification was addressed to Asos's data protection officer and the IT department, claiming that hackers had "completely breached" the data hosted by the company on Snowflake. Snowflake is a technology company that allows corporate clients to analyze large amounts of data. The notification stated, "Contact us, otherwise we will disclose it."

Hackers issue warnings to customers through their own notification systems, attempting to force the company to contact them, otherwise they may release the stolen data online.

According to Bleeping Computer, these hackers are said to have gained access to the Snowflake instance by "pretending to be trusted contacts to obtain login credentials." Snowflake stated that its system itself was not compromised. It is still unclear whether the Snowflake instances operated by Asos had multi-factor authentication enabled. It is also not clear how the hackers obtained system access rights to Asos used for sending in-app push notifications, as such functionality is usually handled by third-party services.

These hackers, who claim to be Xuanye Group, have not yet stated how much data they claim to have in their possession. The Asos website indicates that the company has 17 million customers.

Earlier this year, the fintech giant Betterment also suffered a hacker attack. The hackers took advantage of their access to the company's third-party marketing platform to impersonate the company and send cryptocurrency scam messages to customers. During this attack, the hackers also obtained data such as customer names, email addresses, and phone numbers.

Tip
$0
Like
0
Save
0
Views 20
HKWDB reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
JULES chooses Ekinops network security solutions to enhance web page security and align with the changes in digital usage trends
JULES, headquartered in Lubei and employing 2,800 staff, has chosen the security service edge solution from Ekinops to enhance internet usage visibility, simplify filter policy management, and strengthen employees' protection against web page risks. This solution consists of SWG, local DNS, and CASB components, covering both headquarters and branch office environments.
PR Newswire
·2026-10-09 00:51:07
8
Arctiq has been rated as CRN Triple Crown Award for the third consecutive year
Arctiq announced that CRN has been recognized as the winner of the 2026 Triple Crown Award award, marking the third consecutive year that the company has received this honor. This award is given to solution providers that have made it onto three important lists of CRN.
PR Newswire
·2026-10-09 00:51:03
8
The U.S. Army awards a $14.5 million contract to webAI to deploy AI to soldiers' equipment
The U.S. Army awarded webAI a fixed-price contract worth $14.5 million through Project ARIA, requiring them to deploy AI that can operate in cloud-free, interfered-with, and intermittent network environments onto the devices already carried by soldiers. webAI stated that their software will run directly on the military's existing laptops, handheld devices, and vehicle-mounted computing devices, and will connect the various nodes through their Intelligence Delivery Network.
PR Newswire
·2026-10-09 00:41:36
11
From Uptober to Spooky Szn? Bitcoin Erases Half of Its September Gain
Bitcoin once fell to $81,749.83 during trading, breaking below the support level of $82,776.30 set yesterday. Spot Bitcoin ETF recorded a net outflow of $484.9 million on October 7th, marking its worst single-day performance since June; within 24 hours, approximately $429 million was liquidated, with 87.5% coming from long positions.
Decrypt
·2026-10-09 00:41:35
10
Bitcoin Approaches Three-Week Lows as U.S.-Iran Military Risks Drive Up Oil Prices
Bitcoin fell to $81,000 after the opening of U.S. markets on Thursday, approaching the key support level of $82,500; at the same time, concerns over potential new military actions by the United States against Iran drove up oil prices, and the yield on U.S. 30-year Treasury bonds also rose to a multi-year high.
Cointelegraph
·2026-10-09 00:41:33
12
View More