ASOS Breach Reveals the Risks in Customer-Facing SaaS
A threat actor, identifying as "Xuanye Group," breached ASOS and gained access to a significant amount of customer data, including contact details, search histories, and customer IDs.
6 article(s) in our index mention this organisation.
A threat actor, identifying as "Xuanye Group," breached ASOS and gained access to a significant amount of customer data, including contact details, search histories, and customer IDs.
Hackers gained access to an ASOS employee account by impersonating a trusted contact, allowing them to send a rogue push notification to customers.
The incident was claimed by a group calling itself Xuanye Group, potentially linked to Chinese threat actors.
Asos customers are receiving fake notifications claiming a Snowflake instance has been compromised, threatening to leak data.
Shares in British clothing company ASOS dropped significantly after customers received a push notification claiming the company had been hacked. The company has not responded to requests for comment.
This article discusses the growing challenge of "code sprawl" driven by the increasing accessibility of AI coding tools like Claude and Lovable. Organizations are struggling to maintain visibility and control as employee…