Particle.news

Unauthorized 'ASOS HACKED' Push Alert Claims Snowflake Compromise

The retailer has restricted access to notification systems and called in national cyber experts as investigators probe whether third‑party messaging services or customer data were accessed.

Overview

  • Thousands of ASOS app users received an unauthorized push notification on Tuesday telling the company’s data protection and IT teams that attackers had “fully compromised the Snowflake instance” and directing recipients to a Telegram channel.
  • ASOS confirmed the rogue alert and says it is investigating unauthorized activity involving third‑party platforms used to communicate with customers, restricting access to those notification systems while its internal and external specialists work the case.
  • The company warns that basic personal information such as names and contact details may have been exposed but says it does not believe payment‑card data or account passwords were impacted at this stage.
  • A previously unknown group calling itself Xuanye has posted claims on Telegram about the incident but has not produced verifiable evidence, and the UK’s National Cyber Security Centre is assisting ASOS and leading official support.
  • The alert wiped roughly 10–12% off ASOS shares, regulators may require formal breach notification to the Information Commissioner’s Office within 72 hours if personal data risk is confirmed, and customers are urged not to click the Telegram link and to watch for follow‑on phishing attempts.