On Tuesday morning, numerous Asos app users reported receiving a strange notification addressed to the company's data protection officer and IT teams. The message, headlined "ASOS HACKED," claimed that hackers had fully compromised the Snowflake instance and demanded engagement or threatened to leak data. Asos acknowledged the incident, stating that some basic personal information may have been accessed. The company has since apologized and assured customers that its website and app are operating as usual.

The notification was sent to users in several countries, including the UK, Australia, France, Sweden, and the Republic of Ireland. According to Google's Play Store, the Asos app has been downloaded to Android devices over 10 million times. Asos serves around 17 million customers annually across more than 150 markets. The incident has raised concerns about data security, with cybersecurity experts describing it as a "brazen" extortion attempt.

Cybersecurity experts, including Charlotte Wilson, head of enterprise at Check Point, have advised users not to engage with the notification and to change their passwords as a precaution. Users have expressed concern about potential data leaks, with some questioning the extent of the breach. Asos has stated that it does not believe payment card information or account passwords were affected.

Asos has taken immediate action to restrict access to the notification platforms and is working with specialists within and outside the company, as well as relevant authorities. The National Cyber Security Centre has offered assistance to Asos. Snowflake, whose tools are used by Asos, has found no compromise of its platform but is continuing its investigation.

The incident has had a financial impact, with shares in Asos falling by around a tenth on Tuesday. The company's statement to the London Stock Exchange's Regulatory News Service provides updates to investors. Cybersecurity experts believe that those behind the incident are trying to apply pressure to Asos to meet their demands rather than target its customers.

Users have been advised to be cautious and take steps to protect themselves, including not clicking on links in the notification, visiting Asos's official website directly for updates, and watching out for potential scam emails or texts. Asos has urged customers to shop with confidence while it investigates the incident.

The incident highlights the importance of data security and the potential consequences of a breach. Asos has assured customers that it takes data protection seriously and will provide updates as necessary. The investigation is ongoing, and it remains to be seen what "basic personal information" may have been impacted.

Key points

  • Asos app users received a hacked notification from hackers claiming to have compromised the Snowflake instance.
  • The incident has raised concerns about data security, with experts advising users to take precautions.
  • Asos has assured customers that its website and app are operating as usual and is investigating the incident.

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.