Imagine unlocking your phone only to find your favorite shopping app shouting that it has been hacked. That is exactly what happened to countless ASOS users on Tuesday morning when a rogue push notification popped up on their screens.
The fast-fashion giant has launched an investigation into what it calls “unauthorised activity” involving third-party platforms. The intrusion, which came to light around 10:00 BST, sent shockwaves through the brand’s massive global customer base.
A Bold Extortion Attempt
The alert itself was unusually direct. Bearing the headline “ASOS HACKED,” the message was addressed directly to the retailer’s IT security and data protection teams. It claimed that the attackers had fully compromised the company’s Snowflake database. “Engage with us, or we will leak it,” the message warned, pointing users to a Telegram channel.
For many, the initial reaction was confusion. Jodie, an analyst living in Edinburgh, said she initially assumed it was a clever marketing campaign. “I thought it was some kind of fun promotion, maybe a 50% discount,” she said. But the illusion faded fast. “Then I read the rest of the text. It was clearly meant for their internal IT department.”
Others felt immediate concern. Erin, a student at the University of Sheffield, worried about the safety of her private details. She noted that while she received the alert, her sister did not. “That makes me wonder about the true scale of this,” she said. “Is everyone affected, or just some of us?”
The Retailer’s Response
ASOS acted quickly to lock down its systems. By Tuesday afternoon, the company acknowledged the breach, admitting that some basic personal details may have been accessed. However, they reassured shoppers that financial data and account passwords remain secure. Both the website and mobile app continue to function as normal.
In an email sent to customers later that evening, the company apologized for the disruption and advised users to ignore the alert. So far, the retailer has not notified the UK’s Information Commissioner’s Office (ICO).
While the total number of affected users is still unknown, the reach is likely vast. The ASOS app has over 10 million downloads on Android alone. Reports of the rogue notification have also surfaced from users in Ireland, France, Sweden, and Australia.
How Did It Happen?
Cybersecurity experts are calling this a remarkably brazen tactic. Typically, hackers negotiate quietly behind closed doors. Broadcasting a ransom demand directly to millions of customers is rare.
Charlotte Wilson, head of enterprise at Check Point, said the hackers essentially turned ASOS’s own application into a megaphone for their ransom note. She advised worried customers to change their passwords and stay alert for phishing attempts, though she emphasized there is no need to panic.
Meanwhile, Snowflake, the cloud data firm named in the alert, stated its initial checks found no evidence of a breach on its side. But technical experts suggest the intrusion goes deeper. Dan Bird from Horizon3 pointed out that triggering a push notification requires access to ASOS’s messaging tools, which are entirely separate from a raw data repository. This indicates the hackers may have compromised multiple entry points.
The UK’s National Cyber Security Centre has reportedly offered its support to ASOS as the investigation continues.