Urgent.News

What's breaking now, across thousands of outlets.

Tech

Brecha de datos de ASOS: aviso falso de app secuestrada

La brecha de dato s de ASOS, desatada por un aviso falso de la app, encendió las alarmas de millones de compradores cuando sus propios teléfonos mostraron una advertencia hostil proveniente de la tienda oficial. Bastó con un mensaje emergente para quebrar la confianza del público. El texto amenazaba directamente con publicar registros privados y remitía a un canal externo. Los intrusos no…

A security breach at ASOS caused a false warning from the company's mobile app, alarming millions of shoppers. A single message prompted widespread panic. The threatening text claimed the company would publish private records and directed users to an external channel. Intruders did not breach the central server's defenses; they tricked an employee into revealing internal passwords.

The timeline showed the attack started with a direct impersonation of an employee's identity. With that access, criminals gained control of the communication tools the store uses to send mass messages. The fear was immediate as thousands of users believed their devices were infected. However, the technical reality was different: the alert system worked properly, but the master key to the control panel was in the hands of criminals.

Social engineering proved to be the key to many cloud platforms. The attacker communicated with an employee posing as a known contact and obtained the necessary credentials without raising suspicion. This single username and password combination was enough to breach the third-party platforms integrated into the company's commercial environment.

Once inside, the group issued a mass notification claiming to have taken control of Snowflake's analytical environments and demanded contact with a group identified as Xuanye via private messaging. The company confirmed that attackers gained access to basic customer information, such as full names and contact details. They ruled out that card numbers or personal passwords had been compromised.

The attackers knew that launching a large-scale threat via a native notification would generate brutal media pressure. When an operating system shows a legitimate push notification, the consumer assumes the sender is verified. This is the psychological trick behind such intrusions. The criminals avoid traditional email spam filters and place the hook directly on the locked screen.

The company cut connections with affected providers and issued a warning on its own platform, asking the community to ignore the fraudulent link. The reputational damage in the stock market hit before noon, with a 10% drop in the value of its shares. The collateral danger of contact databases was more than basic contact information.

With names and email addresses, phishing campaigns could be launched. A text message simulating a delayed package or pending refund could convince victims much more when including the person's real name and mentioning recent purchases. If combined with the confusion generated by the initial warning, the stage was set for large-scale scams.

Automated communication channels integrate too many intermediary services. Each tool managing analytical or push message transmissions represents a weak point if it lacks strict cryptographic isolation. Companies protect their master databases with heavy locks, but neglect the marketing panels where they directly speak to people's phones.

Detecting internal session verification issues, this case demonstrates a critical operational gap: the absence of secondary hardware-based validations to authorize mass transmissions. A compromised account should not have the power to draft a message and send it to millions of devices without double supervisory signing. Corporate workflows typically prioritize delivery speed over integrity filters.

If internal software does not require a physical security key or staged approval before executing a campaign that covers the entire user base, stolen credentials can paralyze the business in ten minutes. Protecting against these attacks requires clear defensive measures for users who have the app installed. Do not click on links included in messages that ask you to resolve disputes on foreign networks.

Be wary of calls or emails claiming to solve a problem with your order and asking for passwords or temporary access codes. Control of direct channels will continue under attack as companies fail to require multiple signatures for activating their public mass transmissions.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

What a Drone Adds to a Perimeter Security Assessment

Most perimeter assessments are conducted at eye level by someone walking the fence with a clipboard, which means most perimeter assessments share a blind spot: everything the site looks like from…

  • Drones provide aerial perspective in perimeter assessments, revealing blind spots.
  • RPAS surveys comply with Canadian regulations, requiring registration and pilot certification.
  • Drone surveys offer defensible evidence to resolve disputes and enhance security assessments.

Joining Hacktoberfest 2026

Hi everyone! 👋 I'm kit57, a developer based in Spain, and I'm joining Hacktoberfest 2026. This year's edition is all about building and learning with open-source AI, with community Fests happening…

More from Thursday 8 October →