ASOS App Sends Hacked Alert to Users, Threatening Data Leak
Translated & summarized from N12 by baba
The ASOS app sent a push notification to users, appearing to be from hackers, claiming a breach of the Snowflake system and threatening data leaks. Users are advised to delete the alert and change their passwords, as the breach has not been officially confirmed.
The story in 6 lines · by baba
- ASOS app sent a hacker-like alert to users threatening data leaks.
- The alert claimed a takeover of the Snowflake cloud system.
- Users were advised to delete the notification and not click the link.
- No official confirmation of a breach has been issued.
- Users should change their ASOS account passwords as a precaution.
- A previous incident involved stolen passwords from other services.
Thousands of ASOS app users, including in Israel, received a push notification on Tuesday that appeared to be sent by hackers. The alert, which used the official ASOS app's name and logo, claimed that the company's information systems had been breached and threatened to leak data. The notification included a link to a Telegram channel, but users were advised to delete it immediately and not click the link.
The message, translated freely, stated, "We have completely taken over the Snowflake system. Contact us, or we will leak it." It was addressed to the privacy supervisor and the company's IT team, not to customers. Snowflake is a cloud service used by many companies for storing and analyzing large databases, which can include customer data.
At this stage, it is unconfirmed whether the claim of a data breach is true, and no official confirmation has been issued. It is also unclear how the senders managed to use the official app's notification mechanism to send the message. Users who received the alert were advised not to click on it or the attached link, but to delete it from their devices. As a precaution, it is recommended to change the password for their ASOS account, especially if it is used for other services.
Earlier this summer, ASOS reported unauthorized access to customer accounts in the United States. According to eSecurity Planet, these accesses were due to passwords stolen from other services, not a breach of ASOS's systems. The US law firm Srourian noted that approximately 138,000 customers were affected in that incident. It is currently unknown if there is any connection between that event and the alert sent to users today.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 1Right 2Haredi 1Other 2
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
