App users receive notifications apparently sent by hackers
Key Points:
- ASOS users across the UK received pop-up messages on the retailer's app, apparently sent by hackers attempting to extort the company by claiming to have compromised its Snowflake data storage instance.
- The message, addressed to ASOS's data protection officer and IT team, threatens to leak data unless engaged with, marking an unusual public disclosure of a potential data breach via the company's own app notifications.
- The hackers, calling themselves the Xuanye Group, linked the message to their newly created Telegram channel, signaling a brazen approach by using the app's notification system, which suggests deeper access beyond just the Snowflake platform.
- Cybersecurity experts highlight the severity and unusual nature of the attack, noting that most cyber extortions are conducted privately, and the use of app notifications undermines users' trust in official communications.
- It remains unclear if ASOS is a Snowflake customer or what data might be affected, but the incident raises concerns due to Snowflake's history of high-profile breaches involving other major companies.