Yovao News · The World, In Focus. From Local to Global, Never Miss a Beat

ASOS Confirms Hackers Sent Extortion Notification to App Users

ASOS Confirms Hackers Sent Extortion Notification to App Users

ASOS has acknowledged that cybercriminals sent a threatening notification through its mobile application, marking a brazen attempt at extortion. Dozens of customers reported receiving a message on Tuesday morning that read “ASOS HACKED,” which was addressed to the retailer’s data protection officer and IT teams.

The alert stated that hackers had “fully compromised the Snowflake instance” and warned: “Engage with us, or we will leak it.” The message included a link to a Telegram channel, a tactic that cybersecurity experts described as unusual due to its public nature.

In response, ASOS confirmed it is investigating “unauthorised activity” involving third-party platforms. The company apologised to customers via email, stating that some “basic personal information” may have been accessed but asserting that payment-card details and account passwords were not impacted. ASOS emphasized that its website and app remain operational and urged customers not to engage with the notification.

The incident has caused concern among shoppers globally. Users in the UK, Australia, France, Sweden, and the Republic of Ireland received the alert. Jodie, an analyst from Edinburgh, initially mistook the pop-up for a promotional advertisement before realizing it was a security threat. Others, such as Erin, a student in Sheffield, expressed anxiety over potential leaks of personal data including home addresses and phone numbers.

Charlotte Wilson, head of enterprise at Check Point, characterized the attack as “deeply serious,” noting that the hackers effectively turned the retailer’s own app into a ransom note. However, she advised customers not to panic, recommending they change their passwords and avoid clicking on suspicious links.

Financial markets reacted swiftly, with ASOS shares falling by approximately 10% on Tuesday. The National Cyber Security Centre has offered assistance to the retailer. Meanwhile, Snowflake, the data platform mentioned in the hackers’ message, stated it has found no evidence of compromise to its systems, despite being linked to previous high-profile breaches involving companies like Ticketmaster and Santander.

Cybersecurity experts suggested the public nature of the notification indicates a strategy to apply pressure rather than directly target individual customers. Authorities have not yet been formally notified by the company.

ASOS has urged investors and customers to monitor official channels for updates. Experts recommend vigilance against follow-up scams, advising users to enable two-factor authentication and avoid refund offers sent via email or text.

2 responses to “ASOS Confirms Hackers Sent Extortion Notification to App Users”

  1. Snowflake denying involvement is interesting. I’ll believe it’s secure only after seeing an independent audit.

Leave a Reply

Your email address will not be published. Required fields are marked *