ASOS Shares Fall 13% After Ransom Note Pushed Via Its Own App
TL;DR
- ASOS customers in the UK, US, Germany and Australia received a push notification on October 6 claiming hackers had compromised the retailer's Snowflake instance.
- ASOS shares fell as much as 13% in London and Snowflake fell as much as 3.2% premarket in New York following the alert.
- The notification was signed 'xuanyewengateway' with a Telegram link; ASOS has not confirmed or denied any breach.
ASOS customers who opened their phones on October 6 did not get a sale alert. They got a ransom note, delivered through the retailer's own app.
'Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,' read the notification, which reached users in the UK, US, Germany and Australia. It was signed 'xuanyewengateway' and carried a link to a Telegram channel, the Financial Times reported.
ASOS shares fell as much as 13% in London trading. Snowflake, which ASOS uses to store customer data, dropped as much as 3.2% premarket in New York.
The company has not confirmed or denied a breach. What is confirmed is that someone was able to push an extortion demand through ASOS's trusted customer channel, which is itself a security incident independent of whatever did or did not happen inside Snowflake.
'Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation,' Dray Agha, senior manager of security operations at Huntress, told Cybernews. Sophos researchers noted the handle 'Xuanye' has no prior presence on hacker forums, raising the possibility this is a publicity play rather than a settled breach.
Originally reported by ft.com
Read the original article →Original headline: Hackers Push 'ASOS HACKED' Notification Through Retailer's App Claiming Snowflake Compromise, Stock Falls 13%