ASOS hacked? Customers Receive Threatening Notifications From Hackers, Here’s What We Know
- ASOS app users received threatening notification on Tuesday morning
- The message indicates that the ASOS Snowflake instance has been compromised
- So far there has been no confirmation from ASOS.
Customers of online shopping giant ASOS have received a notification apparently suggesting the site has been hacked.
The message, written by the hackers, was sent via a notification on a mobile app on Tuesday morning.
“Dear ASOS DPO and IT, we have completely compromised the Snowflake instance. Please interact with us or we will leak it,” the message reads, before connecting to a Telegram chat.
Latest videos ofTechnologyRadar
Has ASOS been hacked?
ASOS has not posted any infringement notices at the time of publication, but according to Down Detector, users began reporting issues with the ASOS app just before 10am on Tuesday morning.
The notification is addressed to the ASOS Data Protection Officer. A DPO is responsible for a company’s data security strategy and compliance with key data protection legislation.
Snowflake is a well-known Software as a Service (SaaS) that organizations use as a dedicated cloud environment. A Snowflake ‘instance’ in this sense refers to an organization’s account. Snowflake environments are used to store, process, and analyze data.
The Telegram channel linked in the notification appears to have been set up specifically for the breach and is called “Xuanye Gateway.”
Under UK law, ASOS has to disclose any data breach to the Information Commissioner’s Office within three days and notify those affected when the breach is classified as ‘high risk’.
Pieter Arntz, senior malware intelligence researcher at Malwarebytes, told TechRadar Pro: “It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential reach is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect.”
“Any exposure could reveal a detailed picture of the customer, from browsing and purchasing habits to location and loyalty status. This is valuable profile data, although the connection alone does not establish what attackers could actually access,” Arntz said.
According to ASOS, the online shopping site had 17 million customers in 150 countries. Many of these clients are located in the United Kingdom, where the company’s headquarters are also located. ASOS also has a strong customer base in the European market.
TechRadar Pro has contacted ASOS for comment but has not yet received a response.
What should I do if I received the notification?
If you are one of the many ASOS customers who have received the notification, there are some steps you can take to stay safe until more details are available:
- Do not click on links in any suspicious emails
- Do not click on links in any suspicious text or messages
Other opportunistic cybercriminals could take advantage of the hysteria caused by the notification to trick you into handing over your account details.
Be especially wary of emails telling you that your account has been compromised or asking you to reset your password.
Always check the authenticity of the email address from which you receive any communication to ensure it is a genuine email from the company.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment