TECHNOLOGY

ASOS App Hit By Alleged Hacker Extortion Message Sent Directly To Customers

Dozens of ASOS app users in the UK reported receiving a push notification claiming hackers had compromised the retailer's Snowflake data instance, in an unusually public extortion attempt. ASOS has not yet confirmed or responded to the claims.

Smartphone showing the ASOS shopping app with a notification alert on screenTECHNOLOGY

Image: Getty Images · Uploaded by IntraGoals — usage rights confirmed

ASOS customers across the UK have reported receiving an unusual push notification through the retailer's app, apparently sent by hackers attempting to extort the company.

Dozens of people told the BBC they saw the message pop up on their phone screens. It read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."

ASOS did not immediately respond to the BBC's request for comment.

Charlotte Wilson, head of enterprise at cyber-security firm Check Point, said the incident, if confirmed, would mark an unusually aggressive tactic. "This is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS's own app into their ransom note," she said. "Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company."

The message was addressed to ASOS's data protection officer and IT team, despite being pushed out to ordinary customers. It claims the attackers have "fully compromised the Snowflake instance," a reference to Snowflake, the data storage and analytics company used by numerous major firms to manage customer data.

It is not currently known whether ASOS uses Snowflake's services, nor what data, if any, might be stored there. Snowflake has been linked to a string of high-profile breaches in recent years, including incidents affecting Ticketmaster and Santander.

What sets this case apart is the public nature of the alleged extortion attempt. Cyber criminals typically pursue ransom negotiations privately, betting that discretion will encourage companies to pay quietly rather than risk reputational damage. Broadcasting the threat directly to customers is highly unusual.

The pop-up message included a link to a Telegram channel run by a previously unknown group calling itself the Xuanye Group, which created the channel on the same day. The channel has posted only three times, with the most recent post referencing the alleged ASOS hack.

Dan Bird of cyber-security firm Horizon3 said the method of delivery raises further questions about the scope of the alleged breach. "Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised," he said. "If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door."

The BBC has not independently verified the hackers' claims, and ASOS has yet to issue a public statement addressing the notifications or confirm whether any customer data has been compromised.

Sources and further readingASOS app users receive push notifications apparently sent by hackers ↗
ABOUT THE DESK

Harsh DV

IntraGoals reports on important changes in technology and work. We check each story for clear writing, trusted sources and useful information before it is published.

KEEP READING

Latest from IntraGoals.

All latest stories ↗