ASOS customers received an unusual notification through the fashion retailer’s official mobile app after hackers claimed they had stolen company data and demanded contact from its security team.
The notification was addressed to ASOS’s data protection officer and IT department. It claimed that attackers had compromised the retailer’s Snowflake environment and threatened to leak stolen information unless the company contacted them.
The alert also included a Telegram contact apparently controlled by the attackers. Sending an extortion message through ASOS’s own app meant that customers could see the demand directly on their phones rather than the hackers communicating privately with the company.
ASOS has acknowledged reports surrounding the incident but has not publicly confirmed that a data breach occurred. The company has also not disclosed whether customer information was accessed or how an unauthorized notification was sent through its app.
Separate reporting indicates that ASOS is investigating whether it was hacked, although the company itself has not publicly announced an investigation.
The attackers’ claim about accessing ASOS’s Snowflake environment also remains unverified. There is currently no evidence suggesting that Snowflake itself suffered a wider security breach.
While the unauthorized notification is evidence that something unusual occurred within a system capable of reaching ASOS app users, it does not prove the hackers’ separate claim that they stole customer data.
ASOS’s website and app remained available following the incident. However, news of the possible cyberattack affected investors, with the retailer’s shares falling sharply after reports of the hacker message emerged.
Customers should also be cautious about phishing attempts that could take advantage of the publicity. Scammers often use reports of major cyber incidents to send convincing password-reset, refund, or account-security emails designed to steal login details.