On Tuesday, thousands of ASOS customers received a striking message from alleged hackers via the official app. The hackers claim to have access to the British fashion retailer’s data environment and are threatening to leak data. ASOS is investigating the matter.
Access to all systems?
Users received a push notification titled “ASOS HACKED.” In it, the senders addressed ASOS’s privacy and IT officials directly: “Dear ASOS DPO and IT, we have completely compromised the Snowflake environment. Contact us, or we’ll leak it.” The notification included a link to a Telegram channel belonging to a previously little-known group calling itself the Xuanye Group.
What is particularly noteworthy is that the attackers appear to have used ASOS’s official notification channel. This could indicate that their access extends beyond just a database. Cybersecurity experts emphasize that sending push notifications typically requires access to systems separate from a data environment such as Snowflake.
It is not yet clear whether hackers actually stole customer data. ASOS confirmed to the BBC only that it is investigating the reports. Meanwhile, the website and app continued to function. Snowflake provides cloud technology that enables companies to store and analyze large amounts of data.
Unprecedented approach
The incident is part of a broader series of cyberattacks on retailers worldwide. But the fact that hackers can reach customers directly through the company’s own app is unprecedented and therefore particularly alarming: how reliable are companies’ communication channels anymore? The stock market reacted immediately, sending the stock down by as much as 13%.
How can your company protect itself? And how do hackers actually gain access? In an impressive demonstration, professional hacker Inti De Ceukelaire will reveal the ins and outs of cyberattacks during the “AI in Retail” pre-event at the RetailDetail Night.
Europe - EN
België - NL
Nederland - NL
España - ES
France - FR


