HIGHthreat·

ASOS Confirms Data Breach Following Snowflake Environment Compromise

UK fashion retailer ASOS confirmed a data breach after threat actors sent unauthorized “HACKED” push notifications to customers via its mobile app. The attackers claimed to have exfiltrated customer data from ASOS’s Snowflake cloud data warehousing environment, indicating a compromise of cloud infrastructure.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

UK fashion retailer ASOS confirmed a data breach after threat actors leveraged its mobile app to send unauthorized push notifications to customers. The attackers claimed to have stolen customer data from ASOS’s Snowflake cloud data warehousing environment. This incident highlights the risks associated with third-party cloud service compromises and their potential impact on customer data and brand reputation.

Technical Analysis

  • Threat actors gained unauthorized access to ASOS’s Snowflake cloud data warehousing environment.
  • The compromise enabled the exfiltration of customer data, as claimed by the attackers.
  • Attackers subsequently utilized ASOS’s mobile application infrastructure to send unauthorized push notifications to users, displaying messages such as “HACKED”.
  • The specific method of initial access to the Snowflake environment (e.g., compromised credentials, API key misuse, vulnerability exploitation) has not been publicly detailed.
  • The ability to send push notifications suggests compromise of an API key or service account with permissions to interact with ASOS’s mobile app backend.

Detection

  • Snowflake Audit Logs: Monitor Snowflake LOGIN_HISTORY and QUERY_HISTORY for unusual login locations, IP addresses, user agents, or large-volume data export queries from service accounts or dormant user accounts.
  • API Gateway Logs: Look for unusual or unauthorized API calls to push notification services or customer communication platforms, especially those originating from unexpected source IPs or using compromised credentials.
  • Cloud Access Security Broker (CASB) Alerts: Review alerts related to unusual data access patterns, large data transfers, or suspicious activity within cloud environments like Snowflake.
  • Network Flow Logs: Monitor for unusual outbound connections from cloud environments or internal systems to unknown external destinations, especially large data transfers.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Snowflake – Unusual Login Location

title: Snowflake - Unusual Login Location
id: 9a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d
status: experimental
description: Detects Snowflake logins from IP addresses or locations not typically associated with legitimate access. Requires tuning for known internal/VPN IP ranges.
logsource:
  product: snowflake
  service: login_history
detection:
  selection:
    EVENT_TYPE: 'LOGIN'
    IS_SUCCESS: 'TRUE'
  filter_known_ips:
    CLIENT_IP|startswith:
      - '192.168.'
      - '10.'
      - '172.16.'
      - '172.17.'
      - '172.18.'
      - '172.19.'
      - '172.20.'
      - '172.21.'
      - '172.22.'
      - '172.23.'
      - '172.24.'
      - '172.25.'
      - '172.26.'
      - '172.27.'
      - '172.28.'
      - '172.29.'
      - '172.30.'
      - '172.31.'
  condition: selection and not filter_known_ips
level: high

Snowflake – Large Data Export to External Stage

title: Snowflake - Large Data Export to External Stage
id: f1e2d3c4-b5a6-7890-1234-567890abcdef
status: experimental
description: Detects large data export operations from Snowflake to external stages, which could indicate data exfiltration.
logsource:
  product: snowflake
  service: query_history
detection:
  selection:
    QUERY_TYPE: 'COPY_INTO'
    QUERY_TEXT|contains: 'LOCATION='
    BYTES_TRANSFERRED|gt: 100000000 # Example: >100MB transferred
  condition: selection
level: high

Mitigations

  1. Review and Rotate Credentials: Immediately review and rotate all credentials (passwords, API keys, tokens) associated with Snowflake access, especially those used by applications or service accounts. Implement strong, unique passwords and enforce regular rotation.
  2. Enforce Multi-Factor Authentication (MFA): Ensure MFA is enforced for all user accounts accessing the Snowflake environment, including administrative and service accounts where possible.
  3. Audit Cloud Access Policies: Conduct a thorough audit of access controls and permissions within the Snowflake environment, adhering to the principle of least privilege. Remove unnecessary permissions.
  4. Monitor Cloud Activity: Implement continuous monitoring of Snowflake audit logs and integrate them with a SIEM for real-time alerting on suspicious activities, such as unusual login patterns or large data exports.
  5. Secure API Endpoints: Review and secure API endpoints used for mobile application communications, ensuring proper authentication, authorization, and rate limiting are in place.

References

  • https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1537 — Transfer Data to Cloud Account
  • T1567.002 — Exfiltration to Cloud Storage
  • T1078.004 — Cloud Accounts
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,495 input / 1,414 output tokens ·
Reviewed and approved by a human analyst before publication
#uncategorized#cloud#data-breach#high#mobile-app#snowflake