I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze
Braze API keys end up in a dozen CI configs and nobody rotates them. Campaign send is one POST.
I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
You probably found out before they did
Stock down 13% today. Interestingly ASOS has been steadily growing this year, would be interested to see Polymarkets today...
Does Snowflake allow you to push messages via in-app messaging? I didn't think it did. This breach might be a little broader than reported.
I've seen comments from people claiming they used to work at Asos saying that they have a Braze/Snowflake integration, and the push notification was sent from Braze
Yep, my first thought is they probably are probably getting the candidate push notifications from snowflake.
That'll do it. Thank you.
Speculating, but it could also be they don't actually have Braze access, but there is a table in snowflake to schedule push notifications
Or they are lying about having snowflake access and only actually have Braze
Lots of fun possibilities!
The ransom note was addressed to their DPO, customers just got CC'd via push.
Five popups. Five. To read this article that doesn't even tell me what ASOS is.
For others its a huge online fashion retailer in the UK (and maybe elsewhere?).
Maybe the hackers were trying to do us a favor?