Particle.news

ASOS App Broadcasts 'ASOS HACKED' Alert Claiming Snowflake Compromise

The notification suggests attackers may have accessed ASOS's push-notification systems, raising the prospect of regulatory reporting and heightened phishing risk for customers.

Overview

  • Thousands of ASOS app users received a push alert on Tuesday that read, “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” and included a link to a newly created Telegram channel called Xuanye.
  • Security experts say the ability to send official app notifications points to access to ASOS's notification infrastructure or credentials that span multiple systems rather than only a single cloud dataset.
  • ASOS acknowledged it was aware of the reports but has not confirmed a data breach or whether it uses Snowflake, and the attackers' claim of a Snowflake compromise remains unverified.
  • The incident triggered hundreds of outage reports to Downdetector and an immediate market reaction with ASOS shares falling about 10–12% in early trading on Tuesday.
  • Cyber advisers warned customers not to click the Telegram link, to watch for follow-up phishing attempts, and noted that if personal data were confirmed exposed ASOS would likely face regulatory notification requirements under UK rules.