Particle.news

ASOS Confirms Customer Data Access After Rogue App Notification

Credentials taken through employee impersonation allowed attackers to use third‑party messaging tools to send a fake alert that may have exposed names and contact details.

Overview

  • Thousands of ASOS app users received an unauthorized push notification on Tuesday claiming a Snowflake breach and linking to a Telegram channel, prompting the company to open an investigation.
  • ASOS says investigators found an attacker impersonated a trusted contact to obtain an employee’s login details and then used those credentials to access third‑party customer‑communication platforms.
  • The retailer warns that basic personal information, including names and contact details, may have been accessed while payment‑card data and account passwords do not appear to have been affected.
  • A previously unknown group calling itself Xuanye Group posted on Telegram claiming it held ASOS customer information and used the message as an extortion tactic, but it has not published verifiable data.
  • ASOS has locked down the affected platforms, engaged the NCSC and law enforcement, warned customers to ignore the Telegram link, and saw its shares fall more than 10% after the alert which increases phishing risk for users.