Reported by 1 source

The short version

  • Users of the ASOS mobile application reported receiving pop-up messages claiming hackers had compromised the company's data systems.
  • The notifications, addressed to internal IT and data protection teams, included a link to a Telegram channel operated by a group calling itself Xuanye Group.
  • Security experts note that sending such alerts suggests attackers may have accessed multiple systems beyond just the claimed database breach.

Customers of the British online fashion retailer ASOS encountered an unexpected digital intrusion on Monday when their mobile applications displayed pop-up messages appearing to originate from cybercriminals. The notifications, which appeared on screens across the United Kingdom, did not contain standard marketing content or service updates but instead delivered a direct threat aimed at the company's internal leadership.

The text of the message was addressed specifically to ASOS's Data Protection Officer and IT department. It stated that hackers had fully compromised a Snowflake instance, referring to the cloud-based data storage platform widely used by enterprises for managing large datasets. The message warned that unless the company engaged with the attackers, they would proceed to leak the stolen information.

News Journal

This method of communication represents a significant departure from typical ransomware or extortion protocols. Cybercriminals generally prefer to conduct negotiations in private channels to avoid drawing public attention and to maximize leverage through secrecy. By broadcasting their demands directly to consumers via the retailer's own application, the attackers have turned a trusted customer interface into a vehicle for intimidation.

The group behind the intrusion has identified itself as the Xuanye Group. They established a new Telegram channel on the day of the incident, posting only three messages in total. The most recent post detailed the ASOS hack, while previous entries provided minimal context about their operations or broader objectives. This sudden emergence suggests a coordinated effort designed to maximize immediate pressure on the target.

Security analysts have pointed out technical implications regarding the scope of the breach. Charlotte Wilson, head of enterprise at Check Point, described the incident as deeply serious if confirmed, noting that the attackers demonstrated brazenness by hijacking the app's notification system. This capability implies access to infrastructure separate from the data storage claims.

Dan Bird from Horizon3 expanded on this assessment, explaining that delivering a push notification requires control over the company's messaging services. Since these systems are distinct from the Snowflake database platform mentioned in the threat, the incident suggests the criminals may have obtained credentials granting them entry to multiple areas of ASOS's digital environment.

It remains unclear whether ASOS actually utilizes Snowflake for its data operations or what specific information might be at risk. The company has not yet responded to requests for comment regarding the validity of the claims or the extent of any potential compromise. Social media platforms have seen dozens of users share screenshots of the alarming messages, expressing confusion and concern over the nature of the alert.

Snowflake has been involved in several high-profile data breaches recently, affecting major organizations such as Ticketmaster and Santander. However, those incidents typically did not involve public notifications sent to end-users. The current situation highlights a growing trend where attackers seek to amplify their impact by involving third parties, including customers, in the extortion process.

As investigations continue, the focus will likely shift to determining whether any customer data was actually exfiltrated. The unusual nature of this attack underscores the evolving tactics of cybercriminals who are increasingly willing to risk public exposure to achieve their financial goals. Companies face heightened pressure to secure not only their databases but also the channels used to communicate with consumers.

The incident serves as a stark reminder of the vulnerabilities inherent in modern digital ecosystems. When attackers can manipulate trusted applications, they undermine user confidence and create immediate reputational damage. Until ASOS provides official clarification, customers remain uncertain about the safety of their personal information and the integrity of the platform they rely on for shopping.

Sources behind this briefing

Go to the original reporting

  • BBC Business↗ASOS app users receive push notifications apparently sent by hackers