Asos
Incident posture
Timeline
Summary
Asos confirmed that hackers sent an unauthorized push notification through its app displaying the message 'ASOS HACKED' and claiming full compromise of a Snowflake instance while threatening to leak data. The notification reached users in several countries, including Australia, France, Sweden and Ireland, and prompted the retailer to restrict access to the notification platforms and begin an investigation with internal and external specialists. The company stated that only basic personal information may have been accessed, with no evidence that payment-card details or account passwords were compromised, and that its website and app continued to operate normally. The incident contributed to a roughly ten percent drop in the company's share price and led the National Cyber Security Centre to offer assistance, while Snowflake reported no indication of a breach on its own platform.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Tuesday morning, numerous Asos app users reported receiving a push notification that read "ASOS HACKED" and was addressed to the company's data protection officer and IT teams. The message stated that the attackers had fully compromised the Snowflake instance and demanded engagement via a linked Telegram channel, threatening to leak data otherwise. Some recipients initially mistook the notification for a promotional offer before recognizing its nature. Users in the United Kingdom, Australia, France, Sweden and the Republic of Ireland described feeling scared or confused by the unexpected alert. Several individuals expressed concern that personal details such as bank information, home addresses and telephone numbers might have been exposed. The exact number of recipients remains uncertain, though the Asos app has been downloaded more than ten million times on Android devices.
Asos acknowledged the unauthorised customer notification on Tuesday afternoon and said that some basic personal information may have been accessed. The retailer emphasized that it does not believe payment-card data or account passwords were compromised in the incident. Asos stated that its website and mobile application continued to operate normally and that it had taken immediate steps to restrict access to the notification platforms involved. The company announced that it was collaborating with internal specialists, external experts and relevant authorities to investigate the activity. In an email to customers later that evening, Asos apologised for the disturbance and urged recipients not to interact with the notification's link. The retailer assured customers that they could continue to shop with confidence while the investigation proceeded, noting that it would provide updates if the situation changed. Asos also filed a statement with the London Stock Exchange's Regulatory News Service to inform investors, and its share price declined by approximately ten percent on the day.
Snowflake, whose data platform is used by Asos for storage and analysis, informed the BBC that its own investigation was ongoing and that, to date, no evidence of compromise had been found on its systems. The company noted that its services have been implicated in several high‑profile data breaches in recent years. The British retailer has not yet notified the United Kingdom's Information Commissioner's Office about the incident. The BBC reported that the National Cyber Security Centre had offered assistance to Asos in response to the event. Asos serves roughly seventeen million customers annually across more than one hundred and fifty markets worldwide.
Sources
Sources available to members: 1 source.