ASOS app users targeted with ‘hacked’ push notifications

Share


Online fashion giant ASOS is facing a security scare after users of its mobile app received unexpected push notifications claiming the company had been hacked.

Thousands of customers across the UK received the titled alert “ASOS HACKED,” which was directly addressed to the data protection officer and the IT team of the retailer.

The message claimed that the company’s Snowflake cloud environment was completely compromised and demanded that executives engage with the perpetrators via Telegram to prevent data leaks.

Security experts note that a company’s use of its own customer notification channels for ransom demands marks an aggressive escalation in cyber extortion.

Aras Nazarovas, a senior information security researcher at Cybernews, explained that public announcements are designed to trigger immediate panic. “Public announcement of a hack puts psychological pressure on decision-makers, with attackers expecting decision-makers to panic and cave in to their demands.”

However, Nazarovas added that public disclosure would reduce the likelihood of a silent ransom to force companies to Report incidents quickly under UK regulations.

Charlotte Wilson, head of enterprise at Check Point, called it a “deeply serious attack because the hackers seem to have done something particularly brazen: turned ASOS’ own app into their ransom note.” The market reacted immediately, with ASOS shares falling almost 12% following the news.

Added Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes:

“It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect.

“Each exposure could reveal a detailed customer picture, from browsing and purchasing habits to location and loyalty status. That’s valuable profiling data, although the connection alone doesn’t determine what the attackers are actually accessing.”

The incident highlights a growing wave of cyber threats targeting major British retailers. It follows high-profile security incidents affecting companies such as Marks & Spencer, Harrods, and the Co-op. M&S has previously suffered severe disruption as it was forced to shut down its website for several weeks and manage widespread stock shortages following a cyber attack.

As investigations continue, security professionals have warned customers to remain vigilant against secondary phishing campaigns.

For the latest tech stories go to TechDigest.tv


Discover more from Tech Digest

Subscribe to get the latest posts sent to your email.

Leave a Comment