Cyber SecurityNews

ASOS App Hijacked by Hackers in Brazen Public Ransom Demand

Online fast-fashion giant ASOS has launched an urgent investigation after thousands of customers across the UK received a hostile, threatening push notification directly through the company’s official mobile app on Tuesday morning.

The security breach, which occurred around 10:00 AM BST, triggered widespread confusion and panic among shoppers, causing ASOS shares to tumble by as much as 11% to 13% on the London Stock Exchange within hours.

What the Attackers Claims Say

The rogue push notification, explicitly titled “ASOS HACKED,” bypassed typical back-channel ransom negotiations by broadcasting the extortion message directly to consumer phone screens.

Although sent to customers, the text was addressed to the retailer’s IT infrastructure and compliance teams:

“Dear ASOS DPO [Data Protection Officer] and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

The alert directed users to an external Telegram channel, creating an aggressive and highly public extortion environment.


What We Know So Far

  • The Compromised Channel: Security experts from Cypro Cyber Bulletins confirm that attackers successfully hijacked ASOS’s mobile broadcast system. By turning a trusted customer communication tool into a digital ransom note, the hackers achieved immediate public fallout.
  • The Snowflake Connection: The threat actors claim to have breached ASOS’s “Snowflake instance”. Snowflake is a massive, third-party cloud data platform utilized by major global corporations. Snowflake databases have been the focal point of several high-profile corporate data breaches in recent years.
  • Website Status: Despite the push notification breach, the main ASOS website and mobile shopping catalog appear to remain fully online and operational.
  • Data Breach Unconfirmed: While the attackers have successfully proven they can control ASOS’s app notifications, no official source has verified that customer data, passwords, or financial information have actually been stolen. No sample logs or leaked files have been made public.

Cybersecurity analysts are urging calm but advising high vigilance for the retail platform’s 17 million global users.

Marijus Briedis, Chief Technology Officer at NordVPN, warned via The Guardian that high-profile breaches often act as a catalyst for secondary crime:

“Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”

Shoppers are strongly advised not to click the Telegram link provided in the app alert, to watch out for targeted phishing attempts, and to await an official response from ASOS regarding whether a backend data breach truly occurred.

Latest Updates

In a statement to the BBC, data storage company Snowflake says: “As soon as we became aware of the notification that is currently being reported, we began an investigation.

“At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously,” Katherine James, director of Snowflake’s Europe, Middle East, and Africa communications team says.

In a statement this afternoon ASOS have confirmed an “unauthorised customer notification” was sent at around 10am today. 

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers,” it said in a statement.

The retailer said it immediately restricted access to the notification platforms and is working with specialists and relevant authorities. 

It added:

“Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.”


Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.