Thousands of ASOS app users received a push notification claiming that attackers had taken control of the company’s Snowflake instance. ASOS has yet to comment on the incident.
Thousands of users of British online fashion retailer ASOS received a push notification titled “ASOS HACKED” on the morning of October 6. The message was not addressed to customers, but to the company’s data protection officers and IT department.
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” the message said. It also included a link that appears to lead to a Telegram channel operated by the attackers.
ASOS has yet to comment
ASOS has not confirmed an attack or explained how the message could have been sent through its official app. The company initially made no statement on its website or social media channels. It has also so far failed to respond to inquiries from Cybernews and HuffPost UK. It remains unclear what data may be affected or whether customer information was accessed or exfiltrated. At around the same time, outage-tracking service Downdetector recorded reports from nearly 500 users experiencing problems with the ASOS website and app.
Snowflake campaign in 2024
Snowflake is a cloud data platform used by numerous companies to store and analyze business data. In 2024, attackers stole data from the Snowflake accounts of numerous companies in a large-scale campaign, including AT&T, Ticketmaster and Neiman Marcus. Security firm Mandiant notified around 165 potentially affected organizations at the time. According to Mandiant, the attacks were enabled by stolen customer credentials rather than a compromise of Snowflake itself. The affected accounts lacked measures including multi-factor authentication and restrictions to trusted networks.
Whether the current incident is connected to that campaign remains unknown.
(Editorial Team)