Major online fashion retailer ASOS customers receive alarming ‘hacked’ notification

Customers of major online fashion retailer ASOS have received an alarming push notification through the company’s app claiming its systems have been hacked and threatening to leak data.
ASOS is a UK-based online fashion retailer with around 17 million active customers across more than 150 markets worldwide, selling clothing, footwear, accessories and beauty products through its website and mobile app.
The unexpected notification appeared on customers’ phones on Tuesday with the title “ASOS HACKED.” The message, addressed to the retailer’s data protection and IT teams, claimed that a Snowflake instance used by the company had been “fully compromised.”
The sender threatened to leak information unless ASOS engaged with them and included a link directing recipients away from the app.
At the time of writing, ASOS has not publicly confirmed that its Snowflake environment or customer data has been compromised, meaning the claims contained in the notification should not yet be treated as confirmation of a data breach.
Snowflake is a cloud-based data platform used by companies to store, process and analyze large amounts of information. It is not currently clear what information, if any, the person or group behind the message may have accessed.
The fact that the message reached customers through an ASOS app notification raises questions about how access to the company’s notification system was obtained, although it does not by itself prove that the wider systems or data referred to in the message were compromised.
Customers should avoid opening the link included in the notification while the incident remains under investigation. ASOS advises customers generally to be cautious of unexpected links and requests for personal information and says users should keep their app updated and use strong, unique passwords.
The apparent incident follows a separate security issue affecting some ASOS customers in the United States earlier this year. In that case, unauthorized third parties accessed some customer accounts using login credentials obtained from outside ASOS’s systems. There is currently no confirmed connection between the two incidents.
ASOS has been approached by news organizations for comment as further details about Tuesday’s incident are awaited.








