ASOS Confirms Data Breach After Hackers Send Push Notification
Translated & summarized from N12 by baba
Fashion retailer ASOS confirmed a data breach after hackers sent an unauthorized push notification to customers worldwide, including in Israel. The company stated that basic personal information like names and contact details may have been exposed, but not payment details or passwords. The attackers claimed to have accessed ASOS's Snowflake account, a data platform used by many retailers. ASOS's stock fell 12% following the incident, and the UK's NCSC offered assistance.
The story in 6 lines · by baba
- ASOS confirmed a data breach potentially exposing customer names and contact details.
- Hackers sent an unauthorized push notification to ASOS app users claiming system compromise.
- The attackers claimed access to ASOS's Snowflake data platform and threatened data leaks.
- ASOS stated that payment card details and account passwords were not believed to be compromised.
- ASOS's stock price dropped by approximately 12% after the incident was reported.
- Customers were advised to ignore the unauthorized notification and not click any links.
British fashion retailer ASOS confirmed on Friday that a data breach may have exposed basic personal information of customers worldwide, including those in Israel. The company issued a statement after customers received an unauthorized push notification on the ASOS app claiming the company's systems had been compromised. The notification, which included a link to a Telegram chat, stated that attackers had gained full access to the company's Snowflake account and threatened to leak data.
ASOS acknowledged the incident in an official statement and an Instagram story, urging customers to ignore the unauthorized message and not click the provided link. The company is investigating unauthorized activity related to third-party platforms used for customer communication. While immediate action was taken to limit access to notification platforms, ASOS stated that basic personal information, such as names and contact details, may have been exposed. However, they do not believe payment card details or account passwords were compromised.
The attackers claimed to have accessed ASOS's Snowflake account, a platform used by many retailers for storing and analyzing customer data, and which has been linked to previous cyberattacks on major companies like Ticketmaster and AT&T. The breach also raised concerns about the potential exposure of sensitive data like clothing and body measurements, as Snowflake hosts Simon AI, a system that compiles customer behavior and demographic information.
Following the reports, ASOS's stock price dropped by approximately 12%. The UK's National Cyber Security Centre (NCSC) reportedly offered assistance to ASOS. Experts noted that the attackers' ability to send a direct push notification indicates they gained access to at least some connected systems, likely as a tactic to pressure ASOS for a ransom payment. Customers were advised to disregard the notification, avoid contacting the attackers, and rely solely on official company updates.
Mentioned
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Centre 2Other 1
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
