Asos breach: hackers used its own push alerts. Audit your martech
The Asos data breach ran through a third-party messaging platform and its own app push notifications. Audit every martech login before an attacker does.
The Asos data breach did not start with a stolen card database. It started with the tools Asos uses to talk to its customers. On October 6, Asos app users got a push notification titled "ASOS HACKED." It was a ransom note addressed to the company's data protection officer, delivered through the retailer's own app. Asos has now confirmed that customer names and contact details were taken. If you run a store, your email platform, SMS tool, and push service are now part of your attack surface.
What actually happened
According to BleepingComputer, the unauthorized alerts began around 5:00 a.m. ET on October 6. The message said the attackers had "fully compromised the Snowflake instance" and told Asos to engage or see the data leaked. It linked to a Telegram channel run by a group calling itself Xuanye Group.
On October 8, TechCrunch reported that Asos told the London Stock Exchange that attackers broke into a third-party platform that hosts data it uses to communicate with customers. The key facts:
- Data taken: names and contact information. The BBC reported home addresses, phone numbers, email addresses, and profile notes such as site search queries.
- Not taken, per Asos: payment card data and account passwords.
- How they got in: TechCrunch, citing BleepingComputer, says the attackers impersonated a trusted contact to obtain login credentials. Snowflake says its own systems were not breached.
- Scale: unknown. Asos says it has 17 million customers.
It is still unclear whether the Snowflake account used multi-factor authentication, and how the attackers reached the push notification system.
Why it matters for your business
Your customer list lives in five places, not one. Shopify or WooCommerce holds the orders. But Klaviyo, Attentive, OneSignal, your CDP, and your data warehouse each hold a copy, with their own logins. Most stores secure the storefront and forget the rest.
A push or SMS tool is a broadcast weapon. Whoever holds that login can message every customer at once, in your brand's voice. In January, Betterment's marketing platform was used the same way to send a crypto scam.
Social engineering beats passwords. Nobody cracked a key here. Someone was talked into giving one up. MFA that a person cannot hand over (passkeys, hardware keys) and a written rule for verifying credential requests close that gap.
Key takeaways
- Asos confirmed attackers took customer names and contact details from a third-party customer-messaging platform
- The attackers sent a ransom note to customers through the Asos app's own push notifications
- Reports say credentials were obtained by impersonating a trusted contact; Snowflake says it was not breached
- List every martech tool that holds customer data or can message customers, and who can log in
- Require phishing-resistant MFA and remove ex-staff and agency accounts
Do you know every tool that can message your customers? We map your commerce stack, from storefront to SMS, and lock down the logins, API keys, and data copies you forgot about. See how we secure commerce stacks.
Sources: TechCrunch, BleepingComputer.
- #data-breach
- #push-notifications
- #martech-security
- #snowflake
- #ecommerce
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
USPS and Amazon test same-day delivery: your cutoff moved
USPS and Amazon are piloting same-day delivery for packages dropped at midday. What the small pilot means for your shipping promise and order cutoff.
Read itPinterest Beauty Guides: AI writes the salon order for clients
Pinterest's AI Beauty Guides turn hair and nail Pins into salon terms, time, and price ranges. Salons should make their service menu match what the AI says.
Read it