ASOS hacked? Customers receive threatening notification from hackers, here’s what we know
ASOS customers have woken up to a threatening notification
- ASOS app users received a threatening notification on Tuesday morning
- The message states that ASOS' Snowflake instance has been compromised
- There has so far been no confirmation from ASOS
Customers of online shopping giant ASOS have received a notification apparently suggesting the site has been hacked.
The message, written but the hackers, was sent out via a mobile app notification on Tuesday morning.
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it”, the message reads, before linking out to a Telegram chat.
Has ASOS been hacked?
ASOS has not released a breach notification as of the time of publication, but according to Down Detector, users began reporting issues with the ASOS app just before 10am Tuesday morning.
The notification is directed towards ASOS’ Data Protection Officer. A DPO is responsible for a company’s data security strategy and compliance with key data protection legislation.
Snowflake is a well-known Software-as-a-Service (SaaS) that organizations use as a dedicated cloud environment. A Snowflake ‘instance’ in this sense refers to an organization’s account. Snowflake environments are used to store, process, and analyze data.
The Telegram channel linked in the notification seems to have been set up specifically for the breach , and is named the 'Xuanye gateway'.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Under UK law, ASOS has to disclose any data breaches to the Information Commissioner’s Office within three days, and notify those affected when the breach is classified as ‘high risk’.
Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes, told TechRadar Pro, "It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect."
"Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access," Arntz said.
According to ASOS, the online shopping site had 17 million customers across 150 countries. Many of these customers are located in the UK, where the company’s headquarters are also located. ASOS also has a strong customer base in the European market.
TechRadar Pro has contacted ASOS for comment, but has not yet received a response.
What should I do if I received the notification?
If you are on of the many ASOS customers who has received the notification, there are a few steps you can take to stay safe until more details are available:
- Do not click links in any suspicious emails
- Do not click links in any suspicious texts or messages
Other opportunistic cybercriminals could capitalize on the hysteria caused by the notification to trick you in to handing over your account details.
Be especially wary of emails telling you your account has been compromised, or asking you to reset your password.
Always double check the authenticity of the email address you receive any communications from to ensure it is a genuine company email.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.
Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.
Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.