← Back to the feed

ASOS Users Targeted by In-App Extortion Messages Claiming Snowflake Database Breach

Developed over time first seen 10 hours ago

·

ASOS customers received an alarming in-app notification on Tuesday morning claiming hackers had compromised the company's Snowflake database instance and demanding engagement under threat of leaking data. The message was addressed directly to ASOS's data protection officer and IT teams and linked to a Telegram channel, representing an unusually brazen and public extortion attempt, as most cyber-criminal demands are made privately rather than broadcast to millions of users via the company's own notification system.

ASOS confirmed the unauthorised activity and stated that basic personal information may have been accessed, though it asserted that payment card details and account passwords remained secure. The retailer serves approximately 17 million customers annually across more than 150 markets, with the app downloaded over 10 million times on Android; customers in Australia, France, Sweden and Ireland also received the notification. The company's share price fell around 10 per cent on Tuesday as ASOS restricted access to its notification platforms and urged customers not to engage with the message.

  • Hackers sent extortion message via ASOS app to millions of users on Tuesday morning
  • The company confirmed basic personal data may have been compromised, but not payment details
  • Stock price fell 10 per cent as ASOS investigates the brazen breach

New here? Start with this

ASOS customers in the UK received threatening messages that popped up on the retailer's mobile app. The messages were from attackers claiming to have broken into ASOS's Snowflake cloud storage system, which holds customer information, and demanding contact via the messaging app Telegram whilst threatening to publish customer data. The fact that these messages appeared within ASOS's own app suggested the attackers had gained significant access to the company's systems.

Similar extortion campaigns have targeted multiple other companies in recent months, with attackers taking advantage of Snowflake accounts that were not properly secured. Cybersecurity experts say this type of attack has become increasingly common as criminals search for databases that lack adequate protection. The incident has raised concerns about how much customer data may have been exposed and whether the attackers' threats are credible.

ASOS began investigating the incident and contacting affected customers. Law enforcement and cybersecurity teams are assessing the authenticity of the threats whilst the company works to establish what happened to its systems.

Coverage

Cybersecurity Offbeat Software Technology Weird & Viral World

Read the full article at the source →