ASOS ‘hack’ alert live: Latest from security experts as customers receive threatening messages

The attackers didn’t just rob ASOS. They used ASOS’s own voice to tell their customers. That’s not just a data breach. That’s a complete loss of operational control, and the reputational damage from that alone is significant.

Muhammad Yahya Patel, vCISO and Cybersecurity Advisor at Huntress

Now is not the time for Asos customers to panic because very little is known about the severity of the reported data breach. It is best to never open notifications from retailers in text messages or emails and never click on any of the links received. Customers should go directly to the Asos website for more information about the breach. For all organizations, this breach is another reminder of the importance of adopting a breach mentality because incidents will inevitably occur and no company is immune from being attacked. In general, companies that prepare before incidents improve their chances of minimizing disruptions to their businesses. Furthermore, paying ransoms is not worth it because it not only further fuels the ransomware economy, but it does not guarantee that the threat group will hand over the decryption keys upon payment. Maintaining solid backups and scheduling regular tabletop exercises is extremely important. Organizations should also have a crisis response plan available to activate during cyber incidents that ties into the regular scheduling of tabletop exercises, so that stakeholders are familiar with the initial steps and actions to implement when an incident is discovered.

Jeff Wichman, Senior Director of Breach Preparedness and Response at Semperis

Snowflake is an artificial intelligence and data analytics platform used by several organizations. In 2024, ShinyHunters hacked Snowflake instances from over 160 organizations and stole sensitive data that was used for extortion. They used credentials obtained from data thieves for initial access. This recent hack may be similar, although it is not confirmed what the initial access was. Snowflake has published more than 20 vulnerabilities in its products in 2026, including three considered high criticality in September, but none of them are known to have been exploited by threat actors. The threat actors provided a link to a Telegram channel created today that already has more than 150 subscribers. That channel is then linked to a group chat with over 260 participants. “Xuanye” is not a known threat actor, but the name is of Chinese origin, which could indicate a Chinese-speaking threat actor or simply a false flag.

Daniel dos Santos, vice president of research at Forescout

Snowflake is a huge cloud database where retailers often store sensitive customer information, a real concern if cybercriminals have actually accessed it as they claim. The push notification suggests that the attackers have also breached the systems that control the ASOS mobile app. This is clear public extortion. Sending a ransom demand directly to consumers’ devices is an aggressive extortion tactic designed to force the company into a quick negotiation. I strongly recommend buyers be on the lookout for targeted phishing attempts while we wait for official confirmation of a data breach.

Dray Agha, Senior Security Operations Manager at Huntress

It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed picture of the customer, from their browsing and purchasing habits to their location and loyalty status. This is valuable profile data, although the connection alone does not establish what attackers could access.

Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes

Avatar photo

Miraj Islam is a writer and contributor at Oalanbrado, interested in news, current events, technology, lifestyle, and stories that matter to readers. He enjoys researching different topics and turning information into clear, useful, and engaging articles. Through his work, Miraj aims to keep readers informed with fresh perspectives and easy-to-understand content from Brazil and around the world.

Post Comment