Users of the global online fashion retailer ASOS received a notification today reading: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
The notification is followed by a link to a Telegram channel called the Xuanye group gateway.
Snowflake is a cloud platform used to store, process and analyze data. It also allows firms to send push notifications.
The Snowflake platform also offers a solution called Simon AI, which collects a customer’s behavioral, transactional and demographic data in one profile.
The group has posted the following statement on its Telegram channel:
“To clear any confusion, the affected organizations app is safe to use. The incident involves customer information, it is safe on our server, and it will not be touched for a designated period.”
It continued: “Considering the current situation regarding incident disclosure in the cybersecurity landscape, you can thank us for our generous clarity regarding this incident.”
The group also claimed payment information had not been affected.
In a notice sent to investors, ASOS has said that it can “confirm that…an unauthorized customer notification was sent to ASOS customers.”
It added that it is investigating unauthorized activity involving third-party platforms that it uses to communicate with customers.
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
It said that basic personal information, including name and contact details, “may” have been accessed, but it does not believe that payment-card information or account passwords were impacted.
“Customer trust is incredibly important to us, and if the situation changes, an update will be provided,” it said before noting that it has cybersecurity insurance with a “large global provider.”
Cybersecurity industry experts are urging ASOS users and customers to continue exercising caution.
“I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach,” said Dray Agha, senior manager of security operations at Huntress.
Charlotte Wilson, head of enterprise for the U.K. and Ireland at Check Point, added: “Criminals know people will be searching for information about the ASOS hack, and we would expect attempts to exploit that confusion.”
“Customers should be extremely suspicious of emails, texts or messages claiming their ASOS account has been compromised, offering refunds or asking them to reset their password through a link,” she added. She recommended that customers go directly to the ASOS app or website rather than following links sent to them.