Customers of the ASOS retail giant received a push notification from the company's mobile application. The content was directed at company management and IT, and states that an unknown group "Xuanye Gateway" has compromised a Snowflake software instance and prompts the company to get in contact.

 

Snowflake is a data aggregation platform which takes retail data from many sources and allows querying, processing and rules-based alerting. Initial statements from ASOS declare that that have found no such compromise, and they have taken initial steps to restrict access to notification platforms.

 

The incident has been concerning to members of the public who witnessed and interacted with the application. Statistics show that the notification was potentially seen by thousands, who have taken to social media to ask questions and relay their feelings about what happened.

 

Whether the attackers do indeed have full access or not, the primary question regarding the incident is the possibility of access to customer data and the threat of further notifications. Users of the Snowflake platform should undertake immediate security reviews and compromise assesments to determine whether their instances may have been affected in a similar manner.

 

If you think your organisation may be affected by this incident, please reach out to the Integrity360 Incident Response team.

 

Contact Us