ASOS Users Receive Alarming, Unofficial Security Breach Notification
Translated & summarized from Behadrei Haredim by baba
Users of the ASOS shopping app received a suspicious push notification claiming a data breach and access to the Snowflake system. The company has not confirmed the breach, and users are advised to delete the notification and change their passwords.
The story in 5 lines · by baba
- ASOS users received an unusual app notification about a data breach.
- The notification claimed access to the company's Snowflake system.
- ASOS has not officially confirmed the alleged security breach.
- Users are advised to delete the notification and change passwords.
- The method of sending the notification via the official app is unclear.
Numerous users of the shopping app ASOS, including those in Israel, were surprised on Tuesday by an unusual alert sent directly to their devices via the official application. The message, which appeared to originate from a party that had breached the company's systems, claimed that ASOS's information systems had been compromised and that data might be leaked. The notification displayed the official ASOS name and logo and arrived as a standard push notification. Following its appearance, users who received it began sharing screenshots on X (formerly Twitter). However, the message itself was not intended for the company's customers. It was addressed to the privacy supervisor and ASOS's IT team, alleging that the senders had gained access to the company's Snowflake system. The message also included a link to a Telegram channel. According to the content of the notification, the senders claim to have achieved full control over ASOS's Snowflake system and demand contact, threatening to expose the information they possess if their demands are not met. Snowflake is a cloud platform used by organizations for storing, processing, and analyzing large volumes of data, potentially including customer-related information. It remains unclear at this stage whether a breach of ASOS systems has actually occurred, and the company has not officially confirmed that its systems were hacked or that data was transferred to an external party. The method by which the message senders managed to use the official app's notification mechanism to distribute their message is also not understood. Users who received the alert are advised not to open it or click on any attached links, but rather to delete it from their devices. As a precautionary measure, it is also recommended to change the password for the ASOS account, especially if the same password is used for other online services. In the coming days, users should exercise increased caution regarding emails or SMS messages that appear to be official communications from ASOS, particularly if they contain links or requests for personal information.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 1Right 2Haredi 1Other 2
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
