ASOS app users receive push notifications apparently sent by hackers

原始链接: https://www.bbc.co.uk/news/articles/cj62ylzpr6d3o

相关文章

原文

On social media, dozens of people have posted about receiving the message - confused as to what it means.

Although the apparent extortion message has been issued directly to customers, it is addressed to Asos' data protection officer (DPO) and IT team.

The message claims the unnamed hackers have "fully compromised the Snowflake instance".

This refers to the data storage company Snowflake, whose tools are used by dozens of firms for collecting, analysing and storing data.

It is not known if ASOS is a customer of Snowflake or what data, if any, is stored with the service.

But Snowflake has been the subject of many high profile data breaches in recent years and has been linked to incidents targeting services including Ticketmaster and Santander.

It is, however, very unusual for a data breach to be revealed quite so publicly - and for customers to be informed in this manner.

Most extortions and negotiations by cyber criminals are conducted in private, with hackers hoping their discretion will result in a quiet pay-off.

The pop up message contains a link to the hackers' Telegram channel.

The new group is calling itself Xuanye Group and only created it's Telegram channel today.

They have posted only three times with the latest being about the ASOS hack.

Dan Bird, from cyber security firm Horizon3 says the pop up message the criminals sent implies that their access has gone beyond the Snowflake database.

"Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised."

"If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door," he said.

联系我们 contact @ memedata.com