ASOS Users Targeted by In-App Extortion Messages Claiming Snowflake Database Breach
Developed over time first seen 11 hours ago
ASOS customers received an alarming in-app notification on Tuesday morning claiming hackers had compromised the company's Snowflake database instance and demanding engagement under threat of leaking data. The message was addressed directly to ASOS's data protection officer and IT teams and linked to a Telegram channel, representing an unusually brazen and public extortion attempt, as most cyber-criminal demands are made privately rather than broadcast to millions of users via the company's own notification system.
ASOS confirmed the unauthorised activity and stated that basic personal information may have been accessed, though it asserted that payment card details and account passwords remained secure. The retailer serves approximately 17 million customers annually across more than 150 markets, with the app downloaded over 10 million times on Android; customers in Australia, France, Sweden and Ireland also received the notification. The company's share price fell around 10 per cent on Tuesday as ASOS restricted access to its notification platforms and urged customers not to engage with the message.
- Hackers sent extortion message via ASOS app to millions of users on Tuesday morning
- The company confirmed basic personal data may have been compromised, but not payment details
- Stock price fell 10 per cent as ASOS investigates the brazen breach
New here? Start with this
ASOS customers in the UK received threatening messages that popped up on the retailer's mobile app. The messages were from attackers claiming to have broken into ASOS's Snowflake cloud storage system, which holds customer information, and demanding contact via the messaging app Telegram whilst threatening to publish customer data. The fact that these messages appeared within ASOS's own app suggested the attackers had gained significant access to the company's systems.
Similar extortion campaigns have targeted multiple other companies in recent months, with attackers taking advantage of Snowflake accounts that were not properly secured. Cybersecurity experts say this type of attack has become increasingly common as criminals search for databases that lack adequate protection. The incident has raised concerns about how much customer data may have been exposed and whether the attackers' threats are credible.
ASOS began investigating the incident and contacting affected customers. Law enforcement and cybersecurity teams are assessing the authenticity of the threats whilst the company works to establish what happened to its systems.
Full account
Customers of ASOS, the multinational online fashion retailer, received alarming pop-up notifications through the company's mobile application on Tuesday, with the messages purporting to originate from computer hackers making explicit threats. The alerts instructed the company's leadership to engage with the attackers or face the public disclosure of purportedly stolen data.
The threatening message read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," before directing recipients to a Telegram channel associated with a group calling itself Xuanye. The group created its Telegram presence on the day of the incident. Snowflake is a commercial cloud platform utilised by numerous corporations to store, process and analyse business and customer information.
The directness of this extortion attempt has struck cybersecurity analysts as highly unusual. Historically, criminal groups conducting such operations maintain confidentiality, as discretion sometimes convinces targets to comply with ransom demands. This attack instead pursued maximum visibility, with the message transmitted through the company's own trusted communication channel to its entire user base. Security researchers have characterised this approach as a deliberate psychological assault designed to generate panic and pressure ASOS management into immediate action.
The precise scope of any breach remains uncertain, though some technical experts have suggested disturbing implications. The ability to send unauthorised notifications through ASOS's app infrastructure, combined with claims of compromising the Snowflake database, potentially indicates that attackers obtained system credentials granting access to multiple separate systems rather than exploiting a single vulnerability. However, security professionals have cautioned customers that confirmation of stolen financial or personal information has not been verified.
Snowflake, the platform named in the extortion message, has attracted considerable attention from cybercriminals in recent years. The company has been associated with several high-profile breaches affecting major corporations, including a ticketing platform and an international banking group. It remains unclear, however, whether ASOS actually maintains customer data through Snowflake's services or uses alternative data storage solutions.
ASOS had not released a detailed public statement regarding the incident at the time of reporting. The company's website and application continued operating normally despite the infiltration. The retailer, which operates in approximately 150 countries and serves roughly 17 million customers, also owns several subsidiary fashion brands. The company's share price experienced significant decline following news of the breach, and many users responded by deleting stored payment information from their accounts.
Where outlets differ
Daily Mail emphasises financial impact and psychological warfare; BBC prioritises technical implications of multi-system access
Daily Mail reports customer panic and share price decline (11 per cent); BBC does not mention financial or behavioural impacts
Daily Mail treats Snowflake compromise as established fact; BBC notes uncertainty about whether ASOS actually uses Snowflake
Daily Mail includes forward-looking phishing warnings; BBC examines what the breach reveals about access scope
BBC contextualises Snowflake's history with other breaches; Daily Mail does not
BBC emphasises the unusual public nature of extortion in cybercriminal context; Daily Mail frames it as psychological pressure tactic
Coverage
- Daily Mail — Asos investigates app message threatening to expose customer data
- BBC Technology — ASOS app users receive apparent hacker extortion messages across UK
Cybersecurity Offbeat Software Technology Weird & Viral World