British online retailer ASOS is investigating an unauthorized push notification sent to its app users on Tuesday. The alert, which read "ASOS HACKED," claimed the company's Snowflake instance had been fully compromised and threatened a data leak unless the attackers were engaged. The notification was addressed to ASOS's data protection officer and IT team.
The incident was reported by dozens of online retailers, with users in Australia, France, Sweden, and Ireland among those who saw the message. ASOS confirmed the alert was unauthorized and said it is working with internal and external specialists, as well as relevant authorities, to investigate the incident. The company has advised users not to engage with the notification while investigations continue.
According to ASOS, basic personal data may have been accessed, but the company stated it does not believe payment-card details or passwords were affected. The site and app remain operational, and the company took immediate action to restrict access to the notification platforms. ASOS has not yet notified the UK Information Commissioner's Office but has been offered assistance by the National Cyber Security Centre.
Snowflake, the data-analytics provider cited in the hackers' claim, reported no evidence of compromise on its platform. Cybersecurity analysts noted that using a customer-facing app as a public ransom note is an uncommon and aggressive tactic, suggesting the attackers may have obtained credentials for multiple systems.
The incident had an immediate impact on ASOS's stock price, with shares falling roughly ten percent on the London Stock Exchange on Tuesday. The company apologized to users in a follow-up email and is continuing to investigate the incident. ASOS's response to the incident is being closely watched by cybersecurity experts and regulators.
The use of a customer-facing app as a public ransom note is a rare tactic, and experts are speculating about the motivations and capabilities of the attackers. The incident highlights the ongoing threat of cyber attacks to online retailers and the importance of robust security measures to protect customer data.
ASOS's investigation is ongoing, and the company is working to determine the extent of the incident and prevent similar incidents in the future. The incident serves as a reminder of the importance of cybersecurity and the need for companies to be prepared to respond quickly and effectively in the event of a breach.
Key points
- ASOS is investigating an unauthorized push notification sent to its app users, claiming a data breach.
- The incident may have involved the compromise of basic personal data, but payment-card details and passwords are believed to be unaffected.
- The incident highlights the ongoing threat of cyber attacks to online retailers and the importance of robust security measures.