Security1 publisher2 min readPublished
Phishing reached AAFES shoppers through the exchange's own app notifications
The Army and Air Force Exchange Service says it is investigating suspicious emails and app push notifications sent to its customers, and it has not said yet whether its own systems or a partner's were involved.
The Watch · Security desk

What happened
- AAFES is investigating a series of suspicious messages sent to its customers through both email and its official app, with the origin and impact still unresolved.
- Customers began posting about the messages on social media last week, showing email from an account impersonating AAFES and one message carrying a link to a "wish list".
- AAFES says direct notification to impacted customers is its standard procedure if personally identifiable information turns out to be compromised.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability Whoever sent these messages could place phishing inside a first-party app, where it appears with the retailer's name and icon and the recipient has no headers or sender domain to check.
- exposure Customers who installed the app are reachable without any mail path at all, so the spam filtering that catches impersonation email never sees this traffic.
- constraint Remediation sits entirely with AAFES and any partner holding its push credentials; the advice given to customers asks them to distrust a channel they cannot configure or filter.
- contradiction The account describes an impersonating account and confirms delivery through AAFES's own app, and those two facts point at different root causes with different clean-up work.
A push notification arriving in the official AAFES app has to be sent by something that app already trusts: the push credentials, the platform holding them, or an account with permission to use either. Email works nothing like that, and a sender address can be forged from anywhere. The brief from scworld.com credits DefenseScoop. It puts both channels in the same campaign: email from an account impersonating AAFES, one message carrying a link to a "wish list", and the same messages also distributed through the official app.
AAFES's own guidance points at the app channel. Julie Mitchell, vice president for AAFES's marketing customer engagement, advised customers to delete any unexpected or suspicious emails or push notifications. She also told them not to click links, open attachments, or share personal or payment information.
The exchange says it is still investigating the origin and impact, and the only impact figure so far is a slight increase in customer calls. The brief carries no recipient count and no date for the first message. Customers began reporting them on social media last week.
Unnamed experts cited in the brief suggest that the targeting, and the information needed to address customers this way, could indicate a security breach within AAFES or at a third-party partner. AAFES has not confirmed either. The exchange did say that direct notification to impacted customers is standard procedure when personally identifiable information is compromised. That notification is the step that would tell customers whether records were touched.
Separating the two possibilities does not require the forensic report. A stolen mailing list explains the email and leaves the push notifications unexplained; access to the system that holds customer tokens explains both. AAFES has notified account holders and issued warnings on social media urging customers not to click suspicious links or provide personal information.
What to watch
- A direct notification letter from AAFES would be the first confirmation that customer records, not just the send channel, were reached.
- Whether AAFES names a third-party marketing or customer-engagement provider when it reports on the origin.
- Further push notifications arriving after AAFES rotates credentials would indicate the access is still live.