‘ASOS hacked’: App customers obtain notifications apparently despatched by hackers

On social media, dozens of individuals have posted about receiving the message – confused as to what it means.
Although the obvious extortion message has been issued on to prospects, it’s addressed to Asos’ knowledge safety officer (DPO) and IT workforce.
The message claims the unnamed hackers have “absolutely compromised the Snowflake occasion”.
This refers back to the knowledge storage firm Snowflake, whose instruments are utilized by dozens of corporations for amassing, analysing and storing knowledge.
It isn’t recognized if ASOS is a buyer of Snowflake or what knowledge, if any, is saved with the service.
But Snowflake has been the topic of many excessive profile knowledge breaches lately and has been linked to incidents focusing on companies together with Ticketmaster and Santander.
It is, nonetheless, very uncommon for an information breach to be revealed fairly so publicly – and for patrons to learn on this method.
Most extortions and negotiations by cyber criminals are carried out in personal, with hackers hoping their discretion will lead to a quiet pay-off.
The pop up message comprises a hyperlink to the hackers’ Telegram channel.
The new group is asking itself Xuanye Group and solely created its Telegram channel right this moment.
They have posted solely thrice with the most recent being in regards to the ASOS hack.
Dan Bird, from cyber safety agency Horizon3 says the pop up message the criminals despatched implies that their entry has gone past the Snowflake database.
“Sending a push notification to ASOS’s app customers would require entry to the corporate’s notification system, which is separate from the Snowflake knowledge platform the attackers declare to have compromised.”
“If each claims maintain up, it suggests the attackers acquired maintain of credentials that opened a couple of door,” he stated.
