ASOS App Sends Hacked Alert to Users, Threatening Data Leak
Translated & summarized from Mako by baba
The ASOS app sent a push notification to users, appearing to be from hackers, claiming a breach of the Snowflake system and threatening data leaks. Users are advised to delete the alert, not click the link, and change their passwords.
The story in 5 lines · by baba
- ASOS app sent a push notification claiming a system breach and data leak threat.
- The notification appeared to be from hackers and mentioned the Snowflake system.
- Users were advised to delete the alert and not click the provided link.
- ASOS has not officially confirmed the breach, and its validity is unconfirmed.
- Users are recommended to change their ASOS account passwords as a precaution.
Thousands of ASOS app users, including in Israel, received a push notification on Tuesday that appeared to be from hackers. The message, sent through the official ASOS app, claimed that the company's information systems had been breached and threatened to leak data. The notification included a link to a Telegram channel, but users were advised to delete it immediately and not click the link.
The alert featured ASOS's official name and logo and was addressed to the privacy officer and IT team of the company, not its customers. It stated, "We have completely taken over the Snowflake system. Contact us or we will leak it." Snowflake is a cloud service used by many companies for storing and analyzing large databases, which can include customer data.
At this stage, it is unconfirmed whether the claim of a data breach is true, and no official confirmation of such a breach has been released. It is also unclear how the senders managed to use the official app's notification mechanism to send the message. Users who received the alert were advised not to click on it or the attached link, but to delete it from their devices. As a precaution, it is recommended to change the password for the ASOS account, especially if it is used for other services. Users should also be wary of emails or SMS messages claiming to be from ASOS in the coming days.
Earlier this summer, ASOS reported unauthorized access to customer accounts in the United States. According to eSecurity Planet, these accesses were due to passwords stolen from other services, not a breach of ASOS systems. The American law firm Srourian noted that approximately 138,000 customers were affected in that incident. It is currently unknown if there is any connection between that event and the alert sent to users today.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 3Right 4Haredi 1Other 2
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
