I received the push notification via the app this morning as well. Extremely bizarre and not how normally one finds out about a company getting hacked.
I am genuinely impressed at the lack of tech literacy in the live feed about this from the beeb.
> Asos did not immediately respond to the BBC's requests for comment.
Amazing how companies think if they say nothing it'll somehow just go away. Couldn't even be bothered to reply to say they're looking into it.
The ransom note was addressed to their DPO, customers just got CC'd via push.
Does Snowflake allow you to push messages via in-app messaging? I didn't think it did. This breach might be a little broader than reported.
Stock down 13% today. Interestingly ASOS has been steadily growing this year, would be interested to see Polymarkets today...
Seems more likely to me that the braze api key was exposed
Five popups. Five. To read this article that doesn't even tell me what ASOS is.
Braze API keys end up in a dozen CI configs and nobody rotates them. Campaign send is one POST.