ASOS Confirms Data Breach Following Snowflake Environment Compromise
UK fashion retailer ASOS confirmed a data breach after threat actors sent unauthorized “HACKED” push notifications to customers via its mobile app. The attackers claimed to have exfiltrated customer data from ASOS’s Snowflake cloud data warehousing environment, indicating a compromise of cloud infrastructure.
Overview
UK fashion retailer ASOS confirmed a data breach after threat actors leveraged its mobile app to send unauthorized push notifications to customers. The attackers claimed to have stolen customer data from ASOS’s Snowflake cloud data warehousing environment. This incident highlights the risks associated with third-party cloud service compromises and their potential impact on customer data and brand reputation.
Technical Analysis
- Threat actors gained unauthorized access to ASOS’s Snowflake cloud data warehousing environment.
- The compromise enabled the exfiltration of customer data, as claimed by the attackers.
- Attackers subsequently utilized ASOS’s mobile application infrastructure to send unauthorized push notifications to users, displaying messages such as “HACKED”.
- The specific method of initial access to the Snowflake environment (e.g., compromised credentials, API key misuse, vulnerability exploitation) has not been publicly detailed.
- The ability to send push notifications suggests compromise of an API key or service account with permissions to interact with ASOS’s mobile app backend.
Detection
- Snowflake Audit Logs: Monitor Snowflake
LOGIN_HISTORYandQUERY_HISTORYfor unusual login locations, IP addresses, user agents, or large-volume data export queries from service accounts or dormant user accounts. - API Gateway Logs: Look for unusual or unauthorized API calls to push notification services or customer communication platforms, especially those originating from unexpected source IPs or using compromised credentials.
- Cloud Access Security Broker (CASB) Alerts: Review alerts related to unusual data access patterns, large data transfers, or suspicious activity within cloud environments like Snowflake.
- Network Flow Logs: Monitor for unusual outbound connections from cloud environments or internal systems to unknown external destinations, especially large data transfers.
Sigma Detection Rules
Snowflake – Unusual Login Location
title: Snowflake - Unusual Login Location
id: 9a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d
status: experimental
description: Detects Snowflake logins from IP addresses or locations not typically associated with legitimate access. Requires tuning for known internal/VPN IP ranges.
logsource:
product: snowflake
service: login_history
detection:
selection:
EVENT_TYPE: 'LOGIN'
IS_SUCCESS: 'TRUE'
filter_known_ips:
CLIENT_IP|startswith:
- '192.168.'
- '10.'
- '172.16.'
- '172.17.'
- '172.18.'
- '172.19.'
- '172.20.'
- '172.21.'
- '172.22.'
- '172.23.'
- '172.24.'
- '172.25.'
- '172.26.'
- '172.27.'
- '172.28.'
- '172.29.'
- '172.30.'
- '172.31.'
condition: selection and not filter_known_ips
level: high
Snowflake – Large Data Export to External Stage
title: Snowflake - Large Data Export to External Stage
id: f1e2d3c4-b5a6-7890-1234-567890abcdef
status: experimental
description: Detects large data export operations from Snowflake to external stages, which could indicate data exfiltration.
logsource:
product: snowflake
service: query_history
detection:
selection:
QUERY_TYPE: 'COPY_INTO'
QUERY_TEXT|contains: 'LOCATION='
BYTES_TRANSFERRED|gt: 100000000 # Example: >100MB transferred
condition: selection
level: high
Mitigations
- Review and Rotate Credentials: Immediately review and rotate all credentials (passwords, API keys, tokens) associated with Snowflake access, especially those used by applications or service accounts. Implement strong, unique passwords and enforce regular rotation.
- Enforce Multi-Factor Authentication (MFA): Ensure MFA is enforced for all user accounts accessing the Snowflake environment, including administrative and service accounts where possible.
- Audit Cloud Access Policies: Conduct a thorough audit of access controls and permissions within the Snowflake environment, adhering to the principle of least privilege. Remove unnecessary permissions.
- Monitor Cloud Activity: Implement continuous monitoring of Snowflake audit logs and integrate them with a SIEM for real-time alerting on suspicious activities, such as unusual login patterns or large data exports.
- Secure API Endpoints: Review and secure API endpoints used for mobile application communications, ensuring proper authentication, authorization, and rate limiting are in place.
References
- https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
T1537— Transfer Data to Cloud AccountT1567.002— Exfiltration to Cloud StorageT1078.004— Cloud Accounts
Generated by
gemini-2.5-flash ·1,495 input / 1,414 output tokens ·
Reviewed and approved by a human analyst before publication