Asos investigates after hackers send extortion push notification to users

Online retailer says basic personal information may have been accessed but no payment or password data compromised

By LineZotpaper
Published
Read Time2 min
Asos customers across the UK received a push notification from the retailer's app on Tuesday claiming hackers had compromised the company's Snowflake data storage instance, prompting an immediate investigation by the company and assurances from Snowflake that its platform was not breached.

The online fashion retailer sent a push notification to users on Tuesday morning that appeared to originate from hackers attempting to extort the company. The message read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."

Asos later issued emails to customers apologising for the "unauthorised push notification" and urged recipients not to click on any links within the message. The company said it had taken immediate action to restrict the suspected hackers' access and was working with advisers and relevant authorities on next steps.

In a subsequent update on Tuesday evening, Asos told customers that the incident may have involved access to "basic personal information including name and contact details." The company stated that it did not believe payment-card information or account passwords had been impacted.

Data storage company Snowflake told the BBC its own investigations had found no compromise of its platform.

Security experts recommend that users who received the notification change their Asos password if they use it elsewhere, enable two-factor authentication where available, and remain vigilant against phishing attempts that may follow the breach.

§

Analysis

Why This Matters

  • The incident highlights the risk of push notifications being exploited for extortion and phishing, a relatively new attack vector that can reach users directly on their devices.
  • Asos customers may be targeted in follow-up scams if their names and contact details have been obtained.
  • The scale of access to customer data remains unclear, leaving users uncertain about the safety of their personal information.

Background

Push notification attacks occur when hackers gain access to a company's messaging infrastructure and send fraudulent alerts to users. Such attacks can erode trust in app notifications and create confusion about legitimate communications. Asos is a major online fashion retailer with a large UK customer base.

Key Perspectives

Asos: The company has apologised, restricted the attackers' access, and is investigating with external advisers and authorities. It has provided limited information about what data may have been accessed. Customers: Affected users face uncertainty about whether their personal information is at risk and are advised to monitor accounts for suspicious activity and avoid clicking links in unexpected notifications. Snowflake: The data storage platform says it found no compromise of its systems, suggesting the attack may have targeted Asos's own infrastructure rather than Snowflake's cloud service.

What to Watch

  • Whether Asos confirms any actual data leakage beyond the push notification itself.
  • The outcome of Asos's investigation and any updates from law enforcement or regulators.
  • Whether other companies using similar push notification services report similar incidents.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.