Asos

Asos customers alerted by hackers in cloud storage breach

A push notification from hackers informed ASOS customers that the company's cloud storage had been "fully compromised." That direct alert is unsettling, but it also highlights a growing reality: cloud breaches are…

3 min readTechCrunch
Asos customers alerted by hackers in cloud storage breach

The hackers who breached ASOS didn't quietly exfiltrate data and disappear. They sent a push notification to the fashion giant's customers, announcing that they had "fully compromised" the company's cloud storage. That is not a bug; it is a message. When attackers shift from stealing data to broadcasting their access directly to end users, they are exploiting a fundamental weakness in how companies manage cloud permissions. For any organization that stores customer data in third-party environments, this incident is a clear signal that perimeter-based security is no longer sufficient.

ASOS customers received the alert because the hackers gained enough control over the cloud storage layer to push notifications through the company's own systems. This is not a phishing attack that tricks a user into clicking a bad link. It is a direct compromise of the infrastructure that the brand trusted to separate its internal operations from its customer-facing communications. The breach mirrors patterns we have seen in other large-scale incidents, such as the Danish Data Breach Exposes 8 Million Records Including the Deceased, where attackers accessed cloud-hosted databases containing sensitive identity information. What makes the ASOS case distinct is the theatricality: the hackers used the company's own notification channel to tell users that the wall was gone. That is a humiliation designed to demonstrate control, not just data theft.

The practical lesson for security teams is that cloud storage cannot be treated as a passive archive. Too many organizations still rely on static access controls and periodic audits, assuming that if the firewall is intact, the data is safe. But as we explored in How AI Models Stress-Test Cloudflare's Firewall to Find Its Weaknesses, modern attackers probe for misconfigurations and over-permissioned roles that legacy tools miss. The ASOS breach suggests that the attackers found exactly that kind of gap: a cloud storage bucket with privileges broad enough to send push notifications to customers. That is not a sophisticated exploit; it is a configuration failure with a megaphone.

The shift from human vigilance to automated defenses, discussed in How security engineering is shifting from human vigilance to automated defenses, is directly relevant here. Manual review of cloud permissions scales poorly, especially when a company manages multiple storage environments across different providers. The attackers in the ASOS case did not need to break encryption or bypass authentication; they simply used the credentials that were already in place. The specific takeaway is this: if your cloud storage system allows a compromised account to interact with customer-facing channels, you have already lost the ability to contain a breach. The question every security leader should ask today is not whether their data is encrypted, but whether their cloud permissions would let an attacker send a push notification to their users.

From TechCrunch

The hackers alerted the fashion giant's customers through a push notification that said they had "fully compromised" the company's cloud storage.

Read the original at TechCrunch