Overview
- Multiple ASOS app users received a push notification on Tuesday that read “ASOS HACKED” and directed the company to a Telegram channel to avoid a threatened data leak.
- The attackers’ message claimed they had fully compromised ASOS’s Snowflake instance and demanded contact through Telegram as proof of extortion.
- There is no independent confirmation that any customer data were stolen and ASOS had not publicly confirmed a breach at the time of reporting.
- Delivery through the official app suggests unauthorized access to ASOS’s push-notification system, while the website and app remained reachable and Downdetector logged about 500 problem reports.
- Consumer advisers urged users not to follow the link, to use unique strong passwords and to monitor accounts, and investigators are examining cloud access logs to verify whether data were exfiltrated.