FINDSUPERDEALS

Scope of Asos data breach wider than first reported

Scope of Asos data breach wider than first reported

Trending News I Viral News I World News I News for You -FSD News

The scope of this week’s apparent breach of online retailer Asos’ mobile application appears to be much wider than was initially reported, with a BBC investigation finding that a significant amount of personally identifiable information (PII) was compromised.

The broadcaster said it was contacted by the cyber criminals who hijacked the app’s push notification feature to send messages to customers on Tuesday 6 October.

The gang, which goes by the name Xuanye, claimed it had accessed and stolen not only customer names and contact details such as addresses, emails and phone numbers, but also customer identification numbers and information on searches they made on the retailer’s app or website.

This could enable downstream cyber criminals and fraudsters to create much more detailed profiles of Asos’ customers, enabling more convincing phishing and social engineering attacks.

In an update to customers shared earlier today (Thursday 8 October), Asos said: “We’re sorry for the unauthorised notification some of you received on 6 October and any uncertainty this caused.

“Our priority will always be to protect our customers, to understand exactly what happened and to share accurate information as quickly as possible. Our teams, supported by external experts, have undertaken a detailed investigation over the last 48 hours.

“We discovered that an unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials. Those credentials were then used to access information on certain third-party platforms used by Asos,” the fast-fashion retailer said.

“The affected platforms were immediately locked down, ensuring that no further information could be accesses and a full investigation was launched with the support of both internal and external cyber experts. We are also working with the relevant law enforcement and regulatory authorities.”

Asos said that names and contact details and certain “non-personal” account related information was compromised. It said that no payment card information, or account pblockwords were accessed, and insisted that its services remain safe to use.

It advised customers to remain cautious of unexpected messages or emails claiming to be from Asos.

“We know our customers trust us with their information. We take that responsibility seriously and have already taken additional steps to further strengthen security controls.

“Once our investigation is complete, we will contact customers directly where we believe additional information, support or action may be required,” it said.

The Asos incident appears to be the first major breach orchestrated by Xuanye – which some sources also style as Xuanyewen. According to the BBC’s reporting, the gang said that it had exploited an agentic marketing platform, Simon AI, which had access to Asos’ Snowflake instance. It is understood Snowflake has been conducting a parallel investigation of its own.

Crisis PR

Observers agreed that for Asos, the deepening severity of the incident heralds a potentially serious crisis, both in technological and reputational terms.

“There was no getting away from this one. It didn’t sit in an inbox waiting to be read; it lit up the lock screens of app users, under the Asos name, before the company itself had a statement out,” said Camellia Chan, co-founder and CEO of X-Phy, an AI-backed data protection platform.

“That is what access to a retailer’s communication platforms buys an attacker: a verified, engaged audience with purchase history attached. A message about a problem with this week’s order sent under the retailer’s brand will convert where a cold phishing email never would. The retailer has, in effect, blockembled and qualified the victim pool, and the attackers only needed to borrow the keys. The names and contact details that were taken extend that reach by email and SMS long after the platform itself has been locked down.

“The route in matters as much as the data. The attackers did not need to break the storefront,” she added.

Hayley Goff, CEO of Whiteoaks International, a PR agency, said: “The latest revelations create a second challenge for Asos in maintaining customers’ confidence in what it tells them, as well as its ability to protect their information. With fuller disclosure following the BBC’s intervention, there is a risk customers feel the company is responding to scrutiny rather than keeping them informed.

“Investigations take time, but reblockurance must keep pace with the evidence. Businesses need to distinguish clearly between what they have confirmed and what they are still investigating. When the picture changes, they must explain why,” said Goff.

“For Asos, the priority now is to make clear what the findings mean for customers and how it is addressing the risks. Every update is an opportunity to rebuild credibility or undermine it further.”


fFINDSUPERDEALS

Leave a Reply