MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-06 · via Engadget

Fashion Retailer Asos Targeted in Cloud Platform Breach Demanding Ransom

Image via Engadget
Image via Engadget

Online fashion retailer Asos experienced a security incident involving unauthorized access to its Snowflake cloud platform, with attackers sending push notifications to customers threatening to leak compromised data. The attackers, claiming to represent the Xuanye Group, targeted the company's data protection and IT personnel through the notification system. While customer names and contact information may have been exposed, Asos stated that payment details and passwords were not compromised, and the company's services continued operating normally.

Expanded Detail

The incident represents a notable shift in extortion tactics, as the attackers leveraged the notification system itself as their delivery mechanism rather than contacting the company through traditional channels. By directing their demands to specific personnel via customer-facing alerts, the threat actors demonstrated knowledge of Asos's infrastructure while simultaneously creating public visibility for their claims.

Snowflake, the compromised platform, serves as a critical infrastructure component for many retailers, storing sensitive operational and customer data. The breach underscores the security challenges associated with relying on third-party cloud services, particularly when those services manage both customer communications and demographic information.

Context

The breach could affect millions of Asos customers whose personal information may now be accessible to threat actors, potentially increasing risks for identity fraud and targeted phishing campaigns. The incident may also influence how retailers evaluate their cloud service dependencies and security protocols. Additionally, it could prompt customers to reconsider their trust in e-commerce platforms and may encourage regulators to examine cloud platform security standards across the retail sector.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Engadget →
Related stories
Denmark Confirms Breach Exposing Population Data for Millions via Compromised Business Access · Cybersecurity
Accenture Contractor Dismissed Following Security Lapse in FBI Data Breach · Cybersecurity
Japanese Media Corporation Nikkei Confirms Compromised Employee Email Accounts Used for Mass Phishing · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Asos hit by extortion hack that may have compromised some customer data.” Browse more stories.