Reported by 1 source

The short version

  • Asos users received unauthorized push notifications containing extortion demands from hackers claiming to have compromised the company's data storage infrastructure.
  • The retailer states that while basic personal information may have been accessed, payment card details and account passwords remain secure.
  • Security experts advise customers to avoid clicking links, update passwords, and enable two-step verification to mitigate potential follow-up phishing attempts.

A significant cybersecurity incident involving the British online fashion retailer Asos has raised concerns among its user base after unauthorized push notifications appeared on mobile devices. The messages, which emerged on Tuesday morning, were not official communications from the company but rather extortion demands sent by individuals claiming to have breached Asos’s data systems. The notification text explicitly addressed Asos’s Data Protection Officer and IT department, stating that a Snowflake instance had been fully compromised and threatening to leak data unless the company engaged with the perpetrators.

Asos responded swiftly to the situation, issuing an apology for the unauthorized push notification and instructing customers to disregard the message entirely. The retailer emphasized that users should not click on any external links contained within the pop-up, which directed recipients to a Telegram account. In its statement, Asos confirmed that it had taken immediate action to restrict the apparent hackers’ access to its systems. The company is currently working with security advisers and relevant authorities to determine the next steps in addressing the breach.

News Journal

The scope of the data exposure remains partially unclear, though Asos has provided some initial details regarding what information may have been accessed. The retailer indicated that basic personal information, including names and contact details, might be included in the compromised data. However, it firmly stated that there is no evidence to suggest that payment card information or account passwords have been impacted. This distinction is critical for users concerned about financial fraud, as the core mechanisms for secure transactions appear to remain intact.

Data storage provider Snowflake, whose platform was cited in the hackers’ demands, has conducted its own investigation and reported finding no compromise of its infrastructure. This discrepancy highlights the uncertainty surrounding the technical nature of the breach. While the attackers claimed full control over a specific instance, Snowflake’s assessment suggests that their platform itself may not have been successfully infiltrated. This leaves open questions about how the hackers managed to send push notifications through Asos’s app and what level of access they truly achieved.

Cybersecurity experts are warning that the immediate aftermath of such an incident often presents significant risks due to confusion and heightened anxiety among affected users. Charlotte Wilson, head of enterprise at Check Point, noted that criminals frequently exploit the period following a publicized breach by launching phishing campaigns. These follow-up attacks typically involve emails, texts, or messages claiming that an account has been compromised, offering refunds, or requesting password resets via malicious links. Users are advised to remain extremely suspicious of any unsolicited communications during this time.

To protect themselves, Asos customers are encouraged to take several proactive security measures. Updating passwords is recommended, particularly for accounts that share credentials with other services. Security professionals suggest creating strong, unique passwords that combine numbers, symbols, and mixed-case characters. Additionally, enabling two-step verification for important applications, such as banking and email, is considered one of the most effective defenses against unauthorized access. The National Cyber Security Centre highlights this feature as a critical layer of protection for online accounts.

Consumer rights advocates are also urging caution regarding phone calls from unknown numbers. Kat Cereda, a spokesperson for Which?, advised that individuals should hang up if they receive calls from someone posing as Asos or another organization. Instead of engaging with the caller, users should contact the organization directly through verified channels to confirm any claims. This approach helps prevent social engineering attacks where fraudsters attempt to extract sensitive information by exploiting fear or urgency.

As of Tuesday evening, Asos reported that its website and app were operating normally, allowing customers to continue shopping without interruption. The company reiterated that protecting customer data is a top priority and promised to provide further updates as more information becomes available. With less than twenty-four hours having passed since the initial notifications appeared, many questions remain unanswered regarding the identity of the attackers, their motivations, and the total number of people affected. Users are directed to visit Asos’s official website for verified updates rather than relying on third-party sources or unverified messages.

The incident underscores the ongoing challenges faced by major e-commerce platforms in securing their digital infrastructure against sophisticated cyber threats. While the immediate financial risk to customers appears limited, the potential for identity theft and phishing scams remains high. As investigations continue, the focus will likely shift from containment to understanding the full extent of the breach and implementing stronger safeguards to prevent similar occurrences in the future. The situation serves as a reminder for consumers to remain vigilant and proactive in managing their digital security.

In the coming days, authorities and cybersecurity firms will work to trace the origin of the attack and identify the group responsible. Until then, Asos customers should monitor their transactions for any unusual activity and stay informed through official company channels. The resolution of this incident will depend on the cooperation between the retailer, law enforcement, and technical experts, all of whom are working to mitigate any long-term damage to user trust and data integrity.

Sources behind this briefing

Go to the original reporting

  • BBC Business↗What can I do to protect myself after 'Asos hacked' message?