Online fashion giant ASOS is facing a security scare after users of its mobile app received unexpected push notifications claiming the company had been hacked.
Thousands of customers across the UK received the alert titled “ASOS HACKED,” which was addressed directly to the retailer’s data protection officer and IT team.
The message alleged that the company’s Snowflake cloud environment had been fully compromised and demanded that executives engage with the perpetrators via Telegram to prevent data leaks.
Security experts noted that utilising a company’s own customer notification channels for ransom demands marks an aggressive escalation in cyber extortion.
Aras Nazarovas, a Senior Information Security Researcher at Cybernews, explained that public announcements are designed to trigger immediate panic. “Publicly announcing a hack puts psychological pressure on the decision-makers, with attackers expecting decision-makers to panic and succumb to their demands.”
However, Nazarovas added that public disclosure reduces the likelihood of a quiet ransom payment, forcing firms to report incidents swiftly under UK regulations.
Charlotte Wilson, head of enterprise at Check Point, called it a “deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note.” The market reacted immediately, with ASOS shares dropping nearly 12% after the news.
Added Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes:
“It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect.
“Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access.”
The incident highlights a growing wave of cyber threats targeting major British retailers. It follows high-profile security incidents affecting firms such as Marks & Spencer, Harrods, and the Co-op. M&S previously suffered severe disruptions as it was forced to shut down its website for several weeks and manage widespread stock shortages after a cyber attack.
As investigations continue, security professionals have warned customers to remain vigilant against secondary phishing campaigns.
For latest tech stories go to TechDigest.tvDiscover more from Tech Digest
Subscribe to get the latest posts sent to your email.