British online retailer ASOS confirmed a breach of customer information after hackers accessed a third-party platform used to communicate with customers and sent a notification through the company’s app.
The company told the London Stock Exchange that names and contact details were taken. BBC News reported that the stolen information also includes home addresses, phone numbers, email addresses and notes in customer profiles, including searches made on the ASOS website.
The hackers sent an unauthorized notification through the app, addressing ASOS’s data protection officer and IT department. It claimed the company’s data hosted on Snowflake had been fully compromised and demanded engagement under threat of publishing the stolen information.
BleepingComputer reported that the attackers obtained login credentials by impersonating a trusted contact. Snowflake said its own systems had not been breached. It is not known whether the Snowflake instance used by ASOS had multifactor authentication enabled. The company has not said how the hackers gained access to the app’s push-notification system.
The group using the name Xuanye Group has not disclosed how much data it claims to hold. ASOS says on its website that it has 17 million customers. Earlier this year, hackers used access to fintech company Betterment’s third-party marketing platform to impersonate the company and send customers a cryptocurrency scam. Names, email addresses and phone numbers were also taken in that breach.