ASOS Breach: Potential Data Leak Threatens Millions of Customers
Translated & summarized from Israel Hayom by baba
Fashion giant ASOS is facing a potential major data breach after users, including those in Israel, received a message claiming a full system compromise and threatening to leak customer data. The incident, which reportedly involves the Snowflake data platform, has led to a stock drop and user complaints. Cybersecurity experts warn that if sensitive customer information has been accessed, it could be one of the most severe cyber incidents recently. Users are advised to change passwords and be wary of suspicious communications.
The story in 6 lines · by baba
- ASOS users globally, including in Israel, received a threat message claiming a full system breach and data leak.
- The attackers allegedly gained access to the Snowflake data platform, potentially exposing sensitive customer information.
- ASOS's stock fell nearly 5% amid reports of the breach, affecting millions of active customers worldwide.
- Cybersecurity experts consider a breach of Snowflake a severe incident with access to vast amounts of sensitive data.
- Users are urged to change passwords and avoid clicking suspicious links or messages from ASOS.
- The extent of the breach is still under investigation, with possibilities ranging from notification system access to full system control.
Users of the ASOS fashion app, including those in Israel, received an alarming message Tuesday morning around 10:00 AM, claiming the company's systems had been breached. The message, addressed to the company's privacy officer and IT department, warned of a "full breach" of the Snowflake system and demanded contact, threatening to leak data. A link to a Telegram chat was included.
Simultaneously, approximately 500 users reported issues with the ASOS website and app, according to Downdetector data. The company's stock saw a nearly 5% decline. ASOS, a major fashion retailer with around 17 million active customers globally, has not yet issued an official statement. Under British law, the company is obligated to report security incidents to authorities within three days of discovery and inform affected customers promptly.
It remains unclear whether the breach is a genuine intrusion into data repositories or an exploitation of the app's notification system. Yarin Finian, VP of Product at the Israeli cybersecurity firm Upwind, explained the potential implications. He noted that a platform as large as ASOS operates a complex system managing customer service, orders, supply chains, and data analysis.
"Currently, it appears the attackers gained access to the digital environment, but the extent of the actual intrusion is still being assessed," Finian stated. He suggested the attackers might have accessed only the push notification system, through which the alarming messages were sent. However, he emphasized, "If reports of a breach into the Snowflake system are true, this is one of the most severe cyber incidents we have seen recently."
Finian elaborated that Snowflake, a cloud data platform, is the "beating heart" holding all of the company's data. Gaining administrative privileges there would grant access to highly sensitive information, including customer order histories, credit card details, home addresses, and personal information of millions of customers. "While it's not a bank, it's a huge database. If the attackers managed to control both the notification system and Snowflake, they might currently have full control over ASOS," he warned.
Finian attributed such failures not to sophisticated hacking, but often to human error, misconfiguration, or accidental file sharing. In the age of AI, he added, attackers use automated scanners that rapidly scan the internet. "Previously, such a breach could exist for months before being exploited. Today, the moment a vulnerability is created, attackers find it within seconds."
As a precaution, users are advised to immediately change passwords for ASOS and any other service using the same credentials. They should avoid clicking on any links or responding to messages purportedly from ASOS and delete the alert. Users should await an official company statement confirming the incident is controlled, systems are clean, and data access has been revoked. Finian cautioned, "There is a real concern that attackers will plant malicious buttons or links that will extract further data from you." The presence of the app on a device is not inherently dangerous, as the breach, as far as is known, targets the company's servers, not users' private devices.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 3Right 4Haredi 1Other 3
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
