
Thousands of ASOS users, including customers in Israel, received an unusual push notification through the company's official app on Tuesday claiming that its information systems had been compromised and threatening to leak data. There has been no official confirmation at this stage that ASOS systems or databases were actually breached.
The message appeared as a notification from the official ASOS app and displayed the company's name and logo. It was reportedly addressed to the company's data protection officer and IT team. Numerous users who received the notification shared screenshots on Twitter.
The senders claimed they had gained access to ASOS's Snowflake system and threatened to release information unless the company contacted them. The notification also included a link to a Telegram channel.
Snowflake is a cloud-based data platform used by companies and organizations to store, process, and analyze information. The alleged attackers claimed they had accessed a system containing ASOS data, but it remains unclear whether the claim is genuine or what information, if any, may have been accessed.
One of the main questions surrounding the incident is how the individuals behind the message were able to use the notification mechanism of the official ASOS app. No official explanation has yet been provided.
Users who received the notification are advised not to click on the message or any attached links and to delete it from their devices. As a precaution, users may also want to change their ASOS passwords, particularly if they use the same password for other accounts.
Customers should also remain alert in the coming days for emails or text messages impersonating ASOS and should not provide personal information or login credentials through suspicious links.
The incident comes after reports earlier this year of unauthorized access to ASOS customer accounts in the United States. According to those reports, the accounts were accessed using passwords stolen from other services rather than through a direct breach of ASOS's systems.
According to the U.S. law firm Srourian, whose comments were cited by CyberInsider, approximately 138,000 customers were affected in that incident. There is currently no evidence indicating a connection between that incident and Tuesday's unusual notification.
