On a random Tuesday, you're scrolling through your favourite online fashion store, only to meet a random pop-up message. Unknown to you, this was an attempt by hackers to extort money from the company.
That's essentially what happened to ASOS.
Early this morning, thousands of ASOS customers opened their phones to find a ransom note sent through the retailer's app. It said: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
ASOS is investigating the incident and hasn't confirmed whether its systems or customer data were actually compromised.

What we know so far
The message was sent to ASOS app users across the UK. It claims that hackers had “fully compromised the Snowflake instance” — a cloud data platform used to store and analyse data. The exact data that may have been accessed is not yet known.
The notification included a link to a Telegram channel operated by a group calling itself the Xuanye Group. This group appears to be relatively new, with cybersecurity researchers saying they hadn't previously encountered it. The Telegram channel also included a message claiming that payment information was not affected.
Following reports of the incident, ASOS shares dropped more than 10% on the London Stock Exchange. Its website and app, though, remain operational. ASOS is investigating whether a breach actually took place, while the UK's National Cyber Security Centre is assisting with the investigation.
The ASOS hack incident isn't normal
“If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS's own app into their ransom note,” said Charlotte Wilson, head of enterprise at Check Point.
“Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company.”
Most extortion attempts happen in private. Hackers negotiate with companies quietly, hoping for a payoff. Sending a ransom message directly to customers is a much more public approach.
“Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised,” said Dan Bird from Horizon3.
“If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door.”
The push notification does suggest that someone gained access to at least part of ASOS's systems, but it does not yet prove that the attackers accessed the Snowflake environment or customer data.
The Snowflake connection
Snowflake is a cloud data platform used by thousands of companies to store, process and analyse data. It has been linked to several high-profile breaches, including incidents involving Ticketmaster and Santander.
ASOS's exact relationship with Snowflake, and what data may have been stored there, is still unclear.
“Snowflake is a massive cloud database where retailers typically store sensitive customer information — it is a real worry if cyber criminals have indeed accessed it as they claim,” said Dray Agha, senior manager of security operations at Huntress.
How to stay safe
The attackers' Telegram channel claimed that payment information was not affected, but ASOS has not independently confirmed the full extent of the incident. So customers should still be cautious.
“What customers should be particularly alert to now is what happens next,” said Marijus Briedis, CTO at NordVPN.
“High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order, or claim a refund.”
Here's what to do:
Subscribe for free to continue reading this article
Subscribe SubscribeAlready have an account? Log in
