Leadership1 publisherNot yet confirmed elsewhere3 min readPublished
Hackers delivered their Asos extortion demand through the retailer's own app
Hackers used the Asos app on Tuesday to send UK users an extortion demand claiming they had compromised the retailer's Snowflake instance. Because the demand went to shoppers, the attackers decided when Asos had to speak to customers, before it could say what data, if any, was taken.
The Board Room · Leadership desk
What happened
- Asos emailed customers to apologise for the "unauthorised push notification" and told them to disregard it and not click the external link it carried.
- Later on Tuesday, Asos said it had acted immediately to restrict the apparent hackers' access and was working with advisers and relevant authorities.
- Snowflake, the data storage company named in the message, told the BBC its own investigations had found no compromise of its platform.
- The BBC reported that it is not yet clear who is behind the message, what they want, how many people received it or how many may be affected.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure Anyone who can reach a retailer's push tool can put words in front of its whole app audience under the brand's name, so control of that tool belongs in the same incident plan as the customer database.
- constraint Customers now warned to distrust messages claiming to come from Asos will treat Asos's genuine updates with the same caution, leaving the company fewer trusted ways to explain the scope.
- precedent A ransom note addressed to the data protection officer arrived as a customer alert. Incident plans that assume the first contact from attackers will be private now have a public counterexample.
"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the message read [3]. It was addressed to Asos's data protection officer and IT staff. It was received by Asos app users across the UK, who got it as a pop-up from the app along with a link to a Telegram account [2][5]. The BBC told readers that receiving it did not mean their phones had been hacked [18]. The words came through the retailer's own channel, and customers saw them before Asos had made any statement [6].
Choosing that audience set the company's timetable. By Tuesday evening Asos was telling customers the data involved may include "basic personal information including name and contact details" [8]. "However, we don't believe that any payment-card information or account passwords have been impacted," it said [9]. At the same point, the BBC reported that it was not clear what information, if any, had been accessed [7].
The note claims a compromise of "the Snowflake instance" [3]. Snowflake's denial, given to the BBC, covers its platform [1]. One statement is about a vendor's platform and the other is about the particular instance the attackers say they hold, so both can be true. A retailer whose data sits with a vendor should expect that vendor to make its own statement, and Snowflake's covers only Snowflake's platform. Neither company has said how the attackers got access to the app's push tool, or whether the same access reached the data store the note names.
Charlotte Wilson, head of enterprise at Check Point, said "the biggest immediate risk may be what happens next" [10]. She expects "attempts to exploit that confusion" [11], and advised customers to be "extremely suspicious" of messages claiming their account has been compromised or asking them to click a link to reset a password [12]. That advice also applies to the channels Asos would use for its own follow-up. The company has promised an update "as soon as we have confirmed more information" [15]. The BBC tells readers to go to Asos's official website directly [16]. Kat Cereda, a spokesperson for Which?, says people should hang up on callers who might be posing as Asos and contact the company by separate means [17].
On Tuesday night Asos said its website and app were operating "as normal, and customers can continue to shop with confidence on ASOS as normal" [14]. That statement concerns whether the shop works. The alert concerned who can send a message to every Asos app user under the company's name [2].
In my view, a push tool belongs in the breach plan for two reasons this case shows. It carried an attacker's demand to Asos customers [2]. It is also one of the most direct routes a retailer has to those same customers once it knows what was taken. If the tool is run as campaign software, the people who can send to the whole base are picked so promotions go out fast. If it is run as production infrastructure, with a short list of senders and a second approver on any message to every user, campaigns slow down. The trade-off is marketing speed against control of a channel that has now carried a ransom note. This quarter's choice is how many people can reach every customer at once. The consequence comes in the next incident, when customers who have been told to distrust brand messages [12] have to decide whether the company's own alert is genuine.
What to watch
- Asos's promised further update, and whether it widens the data involved beyond names and contact details or changes its view on payment cards and passwords.
- Any account from Asos or Snowflake of how the attackers reached the app's push tool and the Snowflake instance, and whether one access route covered both.
- Follow-on phishing emails, texts or calls posing as Asos, which Check Point's Charlotte Wilson expects.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives65
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Data storage company Snowflake told the BBC its investigations had "found no compromise" of its platform.
ReportedSupportedSource: Snowflake, to the BBC2 sources— create a free account to open themView cited source - [2]
On Tuesday morning, Asos users across the UK were sent pop-up messages from its app that appear to have been sent by hackers trying to extort the company.
- [3]
"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the message read.
- [4]
Asos emailed customers apologising for the "unauthorised push notification" containing an external link, and said they should disregard the message and not click on it.
- [5]
The hack notification included a link to a Telegram account.
- [6]
Later that day (Tuesday), Asos said it took immediate action to restrict the apparent hackers' access, was investigating and working with advisers and relevant authorities on "next steps".
- [7]
At this stage it isn't clear what information, if any, has been accessed.
- [8]
On Tuesday evening, Asos told customers the data may include "basic personal information including name and contact details".
- [9]
"However, we don't believe that any payment-card information or account passwords have been impacted," Asos added.
- [10]
Charlotte Wilson, head of enterprise at cyber-security firm Check Point: "the biggest immediate risk may be what happens next".
- [11]
Wilson says criminals know people will be searching for information online and expects there to be "attempts to exploit that confusion".
- [12]
Wilson says Asos customers should be "extremely suspicious" of emails, texts or messages claiming their account has been compromised, offering a refund or asking them to click a link to reset their password.
- [13]
It isn't yet clear who is behind the message, what their motivation is, how many people received the notification or how many may be impacted.
- [14]
Asos said its website and app were operating "as normal, and customers can continue to shop with confidence on ASOS as normal" as of Tuesday night.
- [15]
Asos said it will provide a further update "as soon as we have confirmed more information".
- [16]
People should visit Asos's official website directly for updates.
- [17]
Which? spokesperson Kat Cereda says people should hang up if they receive calls from someone they think might be posing as Asos or another organisation, and contact the organisation themselves afterwards through separate means.
- [18]
Receiving the pop-up message does not mean the recipient's phone has been hacked.
Sources
1 independent publisher whose own reporting we read for this story.
- bbc.co.ukWhat can I do to protect myself after 'Asos hacked' message?
1 article · October 6, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.