I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze
As far as I know, the Braze/Snowflake integration is just to pull contact data and event feeds into Braze and to sync out performance data.
If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.
This assumes they implemented things sanely with the db user for Braze having limited access rights…
> Asos did not immediately respond to the BBC's requests for comment.
Amazing how companies think if they say nothing it'll somehow just go away. Couldn't even be bothered to reply to say they're looking into it.
Braze API keys end up in a dozen CI configs and nobody rotates them. Campaign send is one POST.
I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
You probably found out before they did
Why do you have an app installed just to buy clothes
Because I buy a lot of clothes and the ASOS app is well built and its slightly easier to use than the site.
Thanks to this hack I now know what ASOS is.
I am genuinely impressed at the lack of tech literacy in the live feed about this from the beeb.
Seems more likely to me that the braze api key was exposed
The ransom note was addressed to their DPO, customers just got CC'd via push.
Does Snowflake allow you to push messages via in-app messaging? I didn't think it did. This breach might be a little broader than reported.
I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze
Yep, my first thought is they probably are probably getting the candidate push notifications from snowflake.
That'll do it. Thank you.
Speculating, but it could also be they don't actually have Braze access, but there is a table in snowflake to schedule push notifications
Or they are lying about having snowflake access and only actually have Braze
Lots of fun possibilities!
As far as I know, the Braze/Snowflake integration is just to pull contact data and event feeds into Braze and to sync out performance data.
If they’ve gained access to Braze presumably they’ll have access to the contact db stored in there along with whatever other information is pushed in to support segmentation and personalisation but it’s definitely limited in scope vs just gaining access to their snowflake db.
This assumes they implemented things sanely with the db user for Braze having limited access rights…
Stock down 13% today. Interestingly ASOS has been steadily growing this year, would be interested to see Polymarkets today...
Five popups. Five. To read this article that doesn't even tell me what ASOS is.
It’s extremely well known in the UK which is the intended audience, although even here older readers might not have heard of it
Second paragraph mentions that it's a "clothing and beauty store".
It's a BBC article for a British retailer. I reckon the knowledge was reasonably assumed for the intended audience.
https://en.wikipedia.org/wiki/Ad_blocking
For others its a huge online fashion retailer in the UK (and maybe elsewhere?).
Maybe the hackers were trying to do us a favor?