Users of online fashion retailer ASOS’s app received an extortionate alert on the morning of October 6.
The alert claimed that the company’s data platform environment had been seized and threatened to leak information if no action was taken.
However, it has not yet been confirmed whether customer information was actually leaked or what the scope of the breach may be.
3-Line Summary
1. An alert claiming ASOS had been hacked appeared in the app
2. The alert included a Telegram link
3. Whether information was leaked has not been confirmed
An App Alert Threatening to “Leak Information”
The alert received by users claimed that ASOS’s data protection officer and IT department had been completely breached through the Snowflake environment. Snowflake is an online data platform used by multiple companies. The alert said that the company would make the information public if it did not respond and added a link to a Telegram chat.
According to HuffPost UK, related posts continued from around 10 a.m. on Tuesday, October 6. Some users said they had received the same alert. However, it is not known how many users received the alert.
An ASOS customer service representative responded that there was no additional information to share at the time and that the company would provide an update as more became known. This should be distinguished from an official company announcement. At the time of both reports, ASOS had not posted any notice related to the matter on its website or social media accounts.
The App Was Operating, but the Scope of Any Leak Was Unconfirmed
The Independent reported that, separately from the extortionate message, the ASOS website and app appeared to be operating as usual. The fact that a service can be accessed does not by itself establish that there was no breach, but based only on the reported information, a service outage was not confirmed.
Experts said the matter should be viewed as an extortion attempt and that the facts should be verified first. Malwarebytes researcher Peter Arntz explained that there could be an indirect connection between the services ASOS uses for marketing and Snowflake, but said that connection alone does not show what information the attacker actually accessed.
Therefore, it is not yet appropriate to conclude that information such as purchase and search histories, location, or membership tier was exposed. The key unresolved questions are what data was present, whether unauthorized access actually occurred, and whether customer information was taken.
Check Your Account Security Instead of Clicking the Link
It is safer not to click the Telegram link in the alert. Security expert Junaid Ali advised that, in situations like this, people should not follow links in alerts and should watch out for impersonation and further scams.
If you already use an ASOS account, it is helpful to use a long, unique password that is not shared with other services and, where possible, to enable 2-factor authentication. This does not mean that an information leak has been confirmed in this case, but since the extortionate alert was sent publicly, people should remain alert to the possibility of fake guidance designed to use it as bait.
The Independent and HuffPost UK reported that they had not received an immediate response from ASOS at the time of publication. Until the company issues an official statement, it is important not to treat the alert’s claims and the actual outcome of any breach as the same fact.
References
- The Independent, ASOS hacked latest
- HuffPost UK, ASOS 'Snowflake Hack'
- Sky News, ASOS latest
Tags #ASOS #ASOSHacked #ASOSApp #AppAlert #ExtortionAlert #Cybersecurity #DataProtection #DataLeak #Snowflake #Snowflake #TelegramLink #AccountSecurity #2FactorAuthentication