ASOS hacked? Customers receive threatening notification from hackers, here’s what we know

ASOS hacked? Customers receive threatening notification from hackers, here’s what we know

ASOS app users received a threatening notification on Tuesday morningThe message states that ASOS’ Snowflake instance has been compromisedThere has so far been no confirmation from ASOS

Customers of online shopping giant ASOS have received a notification apparently suggesting the site has been hacked.

The message, written but the hackers, was sent out via a mobile app notification on Tuesday morning.

“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it”, the message reads, before linking out to a Telegram chat.

Latest Videos FromTechRadar

Has ASOS been hacked?

ASOS has not released a breach notification as of the time of publication, but according to Down Detector, users began reporting issues with the ASOS app just before 10am Tuesday morning.

A notification distributed by the ASOS app with a message stating that the company's Snowflake instance has been hacked.

(Image credit: Future / Mike Moore)

The notification is directed towards ASOS’ Data Protection Officer. A DPO is responsible for a company’s data security strategy and compliance with key data protection legislation.

You may like

Snowflake is a well-known Software-as-a-Service (SaaS) that organizations use as a dedicated cloud environment. A Snowflake ‘instance’ in this sense refers to an organization’s account. Snowflake environments are used to store, process, and analyze data.

The Telegram channel linked in the notification seems to have been set up specifically for the breach , and is named the ‘Xuanye gateway’.

Under UK law, ASOS has to disclose any data breaches to the Information Commissioner’s Office within three days, and notify those affected when the breach is classified as ‘high risk’.

Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes, told TechRadar Pro, “It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect.”

“Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access,” Arntz said.

What to read next

According to ASOS, the online shopping site had 17 million customers across 150 countries. Many of these customers are located in the UK, where the company’s headquarters are also located. ASOS also has a strong customer base in the European market.

TechRadar Pro has contacted ASOS for comment, but has not yet received a response.

What should I do if I received the notification?

If you are on of the many ASOS customers who has received the notification, there are a few steps you can take to stay safe until more details are available:

Do not click links in any suspicious emailsDo not click links in any suspicious texts or messages

Other opportunistic cybercriminals could capitalize on the hysteria caused by the notification to trick you in to handing over your account details.

Be especially wary of emails telling you your account has been compromised, or asking you to reset your password.

Always double check the authenticity of the email address you receive any communications from to ensure it is a genuine company email.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.