The short version
- Asos stock fell nearly 12% on the London Stock Exchange following widespread reports of malicious notifications sent to mobile app users.
- The messages claimed hackers had fully compromised a Snowflake cloud instance containing sensitive customer data and linked to a Telegram channel.
- Security experts warn that such public extortion tactics often precede targeted phishing campaigns aimed at exploiting consumer anxiety.
Shares in the British online fashion retailer Asos dropped by approximately 12 percent on the London Stock Exchange on Tuesday morning. The sharp decline followed reports that thousands of customers using the company’s mobile application received alarming push notifications. These messages asserted that hackers had completely compromised the retailer’s data infrastructure. Despite the severity of the claims, the Asos website and mobile app continued to function normally during trading hours.
The notification, titled 'Asos hacked,' directed recipients to a channel on the Telegram messaging service. The text within the message addressed the company’s data protection officer and IT department directly. It stated that attackers had gained full control over a Snowflake instance. Snowflake is a cloud-based platform widely used by enterprises to store, process, and analyze large volumes of data. For retailers like Asos, this system often holds transaction records and detailed demographic information, including clothing sizes and body measurements.
Asos has confirmed it is actively investigating the incident. The company has not yet verified whether a breach actually occurred or if the notification was a bluff designed to cause panic. The operational status of the platform suggests that core services remain intact, but the uncertainty surrounding the integrity of customer data has triggered immediate market reaction. Investors appear to be pricing in the potential costs of remediation, regulatory fines, and reputational damage.
Cybersecurity professionals view the method of communication as a significant escalation in extortion tactics. Dray Agha, a senior security operations manager at Huntress, described the move as clear public extortion. He noted that Snowflake databases typically contain highly sensitive consumer information. If criminals have indeed accessed these systems, the implications for privacy are severe. The fact that attackers could send push notifications implies they may have breached the systems controlling the mobile app itself.
Sending ransom demands directly to consumer devices is an aggressive strategy intended to pressure businesses into rapid negotiations. By bypassing corporate communication channels and targeting end-users, hackers aim to create widespread alarm. This approach forces companies to respond quickly to protect their brand image and customer trust. The tactic shifts the burden of anxiety onto shoppers, who may feel vulnerable despite having no direct control over the situation.
Experts warn that high-profile cyber incidents create fertile ground for secondary attacks. Marijus Briedis, chief technology officer at NordVPN, highlighted the risk of phishing campaigns emerging in the aftermath. Criminals often exploit the publicity surrounding a breach to send fraudulent emails and texts. These messages may impersonate Asos officials, asking customers to reset passwords, confirm payment details, or claim refunds.
Shoppers are advised to remain vigilant against such targeted attempts. Verifying the authenticity of any communication from the retailer is crucial before clicking links or providing personal information. The incident underscores the growing sophistication of cybercriminals who leverage public fear to maximize leverage. It also highlights the vulnerability of cloud-based data storage systems when security perimeters are breached.
This event follows a troubling trend of cyberattacks targeting major British retailers. Last year, companies including Marks & Spencer, the Co-op, and Harrods suffered significant cyber incidents. Marks & Spencer and the Co-op experienced stock shortages due to system disruptions. Marks & Spencer was forced to take its website offline for several weeks while working to clean its systems. The recurrence of such attacks suggests a persistent threat landscape for the retail sector.
The situation remains fluid as Asos continues its investigation. Official confirmation of a data breach has not been issued, leaving customers and investors in a state of uncertainty. The company must balance transparency with the need to avoid spreading unverified information. In the coming days, further details regarding the scope of any potential compromise are expected to emerge.
The incident serves as a reminder of the critical importance of robust cybersecurity measures for digital-first businesses. As reliance on cloud platforms grows, so does the potential impact of breaches. Companies must ensure that their security protocols can withstand increasingly aggressive extortion tactics. For consumers, staying informed and cautious is the best defense against opportunistic fraud in the wake of such events.
Sources behind this briefing
Go to the original reporting
- The Guardian World↗Asos customers receive ‘hack’ notification threatening leak