ASOS Customers Receive Push Notifications Claiming the Company Was Hacked

· Original article ↗

Summary

ASOS confirmed an unauthorized customer notification sent through third-party platforms. The notification claimed a Snowflake compromise, but ASOS says only basic personal information may have been accessed; the claim and any data theft remain unverified.

Key points

  • Thousands of customers received an alarming message through the ASOS app claiming the company’s Snowflake instance had been compromised.
  • ASOS confirmed an unauthorized customer notification and said it is investigating activity involving third-party communication platforms.
  • ASOS immediately restricted access to the notification platforms and is working with specialists and relevant authorities.
  • The company said names and contact details may have been accessed, but it does not believe payment-card information or account passwords were affected.
  • The alleged Snowflake compromise and any theft of customer data have not been independently verified; the ASOS website and app remain operational.
  • If customer data was accessed, it could expose shopping and profile information and enable more convincing targeted phishing.

Article Details

Victim Organization
ASOS
Incident Type
Unauthorized customer push notification through the ASOS app; alleged compromise of a Snowflake instance
Data Types Exposed
  • Names (may have been accessed, according to ASOS)
  • Contact details (may have been accessed, according to ASOS)
Operational Impact
Thousands of customers received an unauthorized push notification. ASOS restricted access to the notification platforms while investigating; its website and app remained operational.
Ransom Or Extortion
The notification claimed a Snowflake instance had been fully compromised and threatened to leak it unless ASOS engaged with the sender. The claimed compromise and any data theft are unverified.
Claim Status
confirmed

Threat Actors

Vendors

Products

Industries

Related Articles