ASOS App Hijacked to Deliver Phishing Notifications Disguised as Snowflake Breach Alert
Attackers gained unauthorized access to ASOS's official mobile app notification infrastructure, weaponizing a trusted channel to distribute phishing messages to unsuspecting users. By falsely claiming a Snowflake data breach, they exploited user anxiety around known cloud provider risks to increase click-through rates on malicious links. This attack demonstrates how compromised push notification systems can bypass traditional email phishing defenses, as users inherently trust alerts from apps they've installed. The incident highlights the danger of insufficient access controls around third-party notification APIs and mobile backend services. When a brand's own infrastructure becomes the delivery mechanism, it dramatically erodes user trust and amplifies the attack's effectiveness.
Tactical Insight
Immediate actions
- Audit and rotate all API keys, tokens, and credentials associated with mobile push notification services immediately.
- Disable or restrict unauthorized notification dispatch capabilities while the investigation is ongoing.
- Issue a public advisory to ASOS users warning them not to click links in recent push notifications.
Long-term improvements
- Implement strict role-based access control (RBAC) and multi-factor authentication for all mobile backend and notification management platforms.
- Establish a content approval workflow and allowlist for outbound push notification messages to prevent unauthorized broadcasts.
- Conduct regular third-party penetration testing of mobile app backend infrastructure, including notification pipelines.
Detection measures
- Deploy real-time alerting on anomalous notification dispatch volume or content patterns within mobile backend systems.
- Integrate mobile backend logs with a SIEM to correlate unusual API activity with authentication events.
- Implement user-facing reporting mechanisms (e.g., 'Report this notification') to crowdsource early detection of malicious pushes.