Users of the ASOS app, the famous British brand active in the world of fast fashion, just needed a tap on the screen to discover that something was wrong: a push notification entitled “ASOS HACKED” appeared on the smartphones of thousands of people, in the United Kingdom and beyond. The text, written in English, is not addressed to customers, but to the managers of the company’s IT department and orders them to contact the authors, otherwise threatening to make the data public. The attack appears to have originated from a compromise of a Snowflake instance. According to the platform Downdetectorjust before 10:00 today at least 500 customers reported problems with the ASOS site. Let’s see what this means and what you need to do if you have the ASOS app installed on your device.
The disturbing notification appeared on ASOS customers’ smartphones
The news began to circulate after a disturbing notification appeared on the smartphones of ASOS customers who had installed the official app of the service:
ASOS HACKED. Dear ASOS Data Protection and IT Officers, We have completely compromised the Snowflake instance. Contact us, otherwise we will make the data public.
Whoever wrote the message in the notification claims to have «completely compromised the Snowflake instance”. Snowflake is a cloud platform used by many companies as a kind of digital warehouse where they collect, organize and analyze data. An instance is the environment dedicated to a single company within that service. For an online store, this may be the space in which the information necessary to make the functions relating to login, purchases, payments, returns, assistance, and so on, converge.
A peculiarity of the message sent by the hackers concerns the fact that its recipients are not ASOS customers directly, but rather the DPO (Data Protection Officer), that is, the person designated in the company to supervise the protection of customers’ personal data, and the IT department, therefore the technicians who manage the systems, he is the interlocutor that the hackers wanted to put under pressure.
The reference to Snowflake brings to mind a precedent. In mid-2024, an attacker broke into hundreds of accounts on the platform, exposing hundreds of millions of customer records. The attackers then used stolen login credentials, and then exploited the data found to blackmail the companies. Among the companies involved were well-known names such as Ticketmaster, AT&T and many other companies.
The stakes are also high for ASOS, which ships to more than 150 countries and claims about 17 million customers a year. After news of the attack, the stock market fell by more than 10% in the morning.
For those who have the ASOS app and have received the notification in question, there is not much to do at the moment, other than avoid clicking on the link in the notification and wait for the official press releases from the company: no certain data yet confirms that what the cyber criminals said is true. The investigations have just begun and we await developments on the matter.
The opinion of cybersecurity experts on the attack
One thing is certain: what happened was rather peculiar. Usually, when a group of hackers attacks a system, they conduct such negotiations in private, with the hope of translating this sort of “discretion” into significant profits. This is why the manner of the attack and the fact that it was made so blatantly public has left some experts perplexed. Charlotte Wilson, business manager of the cybersecurity company Check Pointfor example, explained:
If confirmed, this is a profoundly serious attack because the hackers appear to have done something particularly brazen: turning the ASOS app into their ransom note. Millions of people trust app notifications on their phones because they should come directly from the company.
According to Aras Nazarovas, researcher at Cybernews, making the attack public immediately was not an intelligent move on the part of its authors. The expert explained:
Publishing the message via notifications to users is a double-edged sword (…) as it could have a similar effect as an internal message, but now everyone knows about the breach, which significantly reduces the likelihood that the ransomware payment will actually be made.









