ASOS confirms data breach after “HACKED” in-app notifications

Refract AI Intelligence Digest

BLUF

ASOS customers may have had personal data compromised following unauthorized access to the retailer's cloud infrastructure and mobile app.

NEWS

UK fashion retailer ASOS acknowledged a security incident where threat actors sent unauthorized push notifications through its mobile application. The attackers claimed to have exfiltrated customer information from the company's Snowflake data warehouse, prompting an official confirmation of the breach.

Why I Care

This incident highlights risks in cloud data storage and mobile app security, potentially exposing millions of customers to phishing, identity theft, or financial fraud.

Next Steps

ASOS customers should monitor accounts for suspicious activity and enable multi-factor authentication immediately; security teams should audit Snowflake access logs and review mobile app notification permissions.

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.