Product6 publishers3 min readPublished
Extortion note meant for ASOS's IT team lands on customers' phones through the retailer's app
Apparent hackers sent an extortion note through ASOS's app to UK customers, claiming to have "fully compromised" its Snowflake instance. ASOS has not confirmed a breach, so the only compromise anyone has seen is that outsiders could message its app users.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The note was addressed to ASOS's data protection officer and IT team, even though it landed on the phones of ordinary customers.
- The BBC reported it is not known whether ASOS is a Snowflake customer or what data, if any, it stores with the service.
- ASOS has not publicly confirmed a breach or explained how an unauthorised notification was sent through its app.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure Whoever sent the note was able to put text in front of ASOS app users under the retailer's own icon, and customers have no way to tell that message apart from a real one.
- cost ASOS has to answer confused customers in public on a timetable the senders chose, before it has said whether any data was taken.
- decision Any company with an app now has to decide whether the credentials that send push notifications get the same access review as the ones that read customer data.
The people who got the message did what users do with a notification that makes no sense. They posted it. Dozens wrote about it on social media, confused about what it meant, the BBC reported [5]. Dexerto saw one user's screenshot, and others said they had received the same text that Tuesday morning, October 6 [8][7].
The message makes one claim, and the way it arrived shows a second thing. Only the second has been shown to happen. The claim is about data: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." [3] The act is about distribution. Someone sent unauthorised text to ASOS users through the official app [7][10].
Nobody has verified the data claim. The BBC reported that it is not known whether ASOS is a Snowflake customer or what data, if any, it keeps there [11]. According to Dexerto, the notification does not say what was accessed or whether customer information was involved [9]. ASOS has not confirmed a breach or said how the message was sent [10]. It is not yet clear whether the push channel and any Snowflake data were reached in the same intrusion. Naming Snowflake makes the threat sound plausible. Dozens of firms use the platform to collect, analyse and store data [13], and the BBC reported that it has been linked to incidents targeting Ticketmaster and Santander [12].
The addressing is where this becomes a product problem. The note was written to a data protection officer and an IT team, and it went to shoppers [6]. I think the split is deliberate. A demand that lands in a DPO's inbox can be handled inside the company. A demand that lands on customers' lock screens has a public audience before the company has a statement, and ASOS did not immediately respond to the BBC [4].
The users here read a message under the ASOS icon as ASOS talking to them. The BBC reported that what confused them was what it meant [5]. Inside a company, push often counts as a campaign channel, measured on opens. To the person holding the phone, it is the company speaking. If the push console sits with the campaign tools, more people and systems can send a message to every customer than can read the customer database.
The test I would apply tomorrow is a 2x2. One axis counts the accounts, human or machine, whose credentials can send to your full app audience: few or many. The other asks whether a send to the full audience needs a second person to approve it. Few senders plus an approval step is a setup you can explain on Friday. Many senders and no approval is the quadrant where an outsider's text can reach customers before anyone inside sees it. In the two mixed quadrants, I would fix the approval step first. It closes the gap even before you have tracked down every credential.
What to watch
- Whether ASOS confirms it uses Snowflake and says what data, if any, was taken.
- ASOS's explanation of how the notification was sent, which will show whether the push channel and the data claim are one intrusion or two.
- Whether the senders leak data as threatened or push further messages through the app.