
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

We help organizations find and fix the gaps before they make headlines.
Online ‘fast fashion’ retail powerhouse Asos is probing a potentially serious data breach after an apparent compromise of its Snowflake data platform resulted in threatening messages being sent to users of its mobile app.
Summary
Customers across the UK reported receiving notifications headed ‘ASOS HACKED’. The messages read: “Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it.” An Asos spokesperson said: “Asos can confirm that, at around 10am today, an unauthorised customer notification was sent to Asos customers.
“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities. “Basic personal information including name and contact details may have been accessed.
We do not believe that payment card information or account passwords, were impacted,” they said. “Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate,” added the spokesperson. Snowflake also confirmed it was aware of the notification and said it had begun an investigation itself, but at the time of writing there was as yet no evidence to suggest a compromise of its platform akin to a series of breaches that unfolded in 2024 .
Both Asos’ website and app are operating normally and there has been no disruption to its core business. The firm said it holds a cyber insurance policy with a large global provider but noted it was too early to quantify any potential impact on trading. Hackers’ claims The message received by Asos customers also included a link to a channel on social media platform Telegram, which, for operational security reasons, Computer Weekly is not including here.
Should you have received the message, it should not be opened under any circumstances. However, according to the BBC’s Verify service , the channel appears to belong to an operation going by the name Xuanye Group. The BBC reported that messages posted to this channel claim that payment information has not been compromised and that the data stolen was ‘safe on our server’ and will not be released for a ‘designated period’.
The broadcaster has not verified these claims. Virtually nothing is known about the previously unobserved Xuanye Group, although its name and terminology used in its messages suggest that the threat actor may originate in China. The name Xuanye may be a reference to the Qing dynasty Kangxi emperor who ruled from 1661 to 1722.
Eset global cyber security advisor Jake Moore described what was likely “one of the most visible hacks in history”. He said: “The fact the threat actors managed to send a push notification to customers suggests they have gained access to at least some of Asos’ connected systems, but it doesn’t prove their full claims about the extent of the data breach. “The hackers say they have compromised the Snowflake cloud data platform, which would put a lot of customer data at risk.
“By broadcasting their breach directly to Asos app users, the threat actors are likely trying to apply pressure to Asos, showing how extensive their access is so they can leverage some sort of ransom,” added Moore. Next steps With no indication – yet – of what data has been compromised in the Asos hack, Natalie Page, threat intelligence head at Talion , advised Asos customers to use caution online. “Avoid clicking on links in messages from unknown senders, be wary of app notifications and avoiding sharing personal and financial information with unknown senders,” she said.
“Other attackers will likely jump on the incident to send out malicious communications, so customers of Asos should be aware of this social engineering tactic. Page added: “Updating passwords on Asos accounts is also advisable, plus on any other accounts that share the same password. “Asos does not currently offer mandatory multi-factor authentication [MFA] to its customers, but maybe given this incident, it is something the company should consider for the future.
“Alternatively, users can log in using authenticated third-party providers like Google, Apple ID, or Facebook. If those external accounts have MFA enabled, it effectively adds a layer of protection when accessing Asos,” she noted. But with the full story yet to emerge, Boris Cipot, principal security engineer at Black Duck said the hack may yet prove to be a damp squib.
“The ability to send a push notification doesn’t automatically prove access to the data platform the attackers claim to have compromised,” said Cipot. “[Asos’] investigation needs to establish which accounts, credentials, and systems were accessed, and whether any data was taken. “We’ve seen this type of scenario before.
Earlier this year, for example, the D1R group claimed it had breached Synopsys and obtained sensitive customer information, but Synopsys said its investigation found no evidence that its systems or customer technical data had been accessed without authorisation. “We’ve also seen the 0APT group claim large numbers of victims, while security researchers later concluded that many of those claims appeared to be fabricated or involved organisations that had not actually been breached,” he said. “ “That’s why, for Asos and everyone involved, the strongest approach is to keep calm, contain what you can, and investigate.
Treat the attackers’ claims seriously, but don’t treat them as facts. Follow the evidence, not the attackers’ narrative.” Learn more about IT at Asos Earlier this year, the Computer Weekly Downtime Upload podcast met to Przemek Czarnecki, chief technology officer at Asos, to discuss how the company is deploying AI and agentic AI . In 2022, we reported on how ASOS was preparing to go deep into the Microsoft Azure cloud portfolio, as it looked to ramp up its use of data analytics to support its business growth goals .
Amid the first Covid-19 lockdown, Asos rolled out augmented reality technology to let customers see how an outfit might look on them .
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
More security news