
Security
CurityThere’s a certain dark creativity in what happened to ASOS. Hackers who broke into the fashion retailer’s data didn’t quietly threaten executives behind the scenes. They used the company’s own app notification system to tell 17 million customers that their data had been stolen. That’s not just a breach. That’s a public humiliation tactic.
According to TechCrunch, ASOS filed a statement with the London Stock Exchange confirming that hackers accessed a third-party platform the company uses to communicate with customers. Names and contact information were taken. BBC News went further, reporting that the stolen data includes home addresses, phone numbers, email addresses, and notes tied to customer profiles, including website search queries. That last detail matters. Search history is behavioral data. It tells a story about who you are, what you want, and potentially what you’re hiding from people in your household.
The push notification sent by the attackers, who identify themselves as the Xuanye Group, addressed ASOS’s data protection officer and IT department directly. It claimed the group had “fully compromised” the company’s data stored on Snowflake, a cloud data platform used by large corporations to process enormous volumes of information. The message ended with a blunt threat: “Engage with us, or we will leak it.”
Snowflake has denied that its own systems were breached, which puts the failure squarely on how ASOS configured and secured its Snowflake instance. Bleeping Computer reports the attackers got in by impersonating a trusted contact to obtain login credentials. Whether ASOS had multi-factor authentication enabled on that Snowflake account is not confirmed. That gap in the public record is significant. MFA is basic. If it wasn’t in place on an account holding data for millions of customers, that’s a serious lapse.
This breach fits into a broader and troubling pattern. Earlier this year, fintech company Betterment suffered a similar attack where hackers accessed a third-party marketing platform, impersonated the company, and pushed a crypto scam to customers. In both cases, the attackers didn’t need to break through hardened internal systems. They found a softer edge: the marketing and communications infrastructure sitting around the main product.
That’s the real lesson here. Companies invest heavily in securing their core platforms while third-party tools used for customer outreach sit with weaker controls. Those tools hold real personal data and have real access to users. For ASOS customers, the practical risks right now include targeted phishing using their real address and purchase behavior, SIM-swapping attempts using their phone numbers, and physical risks if home addresses end up published. None of those are theoretical. They happen after breaches like this one.
- Data confirmed stolen: names, email addresses, phone numbers, home addresses
- Also taken: customer profile notes, including on-site search queries
- Attack vector: compromised Snowflake instance via credential impersonation
- Extortion method: unauthorized push notification sent through ASOS’s own app
- Attackers: Xuanye Group, with no confirmed volume of stolen records disclosed
ASOS has 17 million customers. The company has not said how many were affected. So, if you shop on ASOS, assume your data is in someone else’s hands until told otherwise.