What's Happening?
ASOS, the British online apparel retailer, is investigating a suspected cyberattack after its mobile app sent push notifications to customers claiming the company's systems had been compromised. The notification,
titled 'ASOS HACKED,' stated: 'Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' This message, which included a link to a Telegram chat, quickly circulated on social media, leading to a sharp fall in ASOS shares. The company confirmed that an unauthorized notification was sent and is investigating unauthorized activity involving third-party communication platforms. While ASOS believes payment card information or passwords were not accessed, basic personal information like names and contact details may have been compromised. Snowflake Inc., a cloud-based data platform mentioned in the hacker's message, stated it found no compromise of its platform.
Why It's Important?
This incident highlights a significant evolution in cyber extortion tactics, where attackers directly leverage a company's customer communication channels to pressure management. By sending a ransom demand via the ASOS app, the hackers created immediate public pressure and fear among customers, impacting the company's reputation and stock value. The use of a trusted app for such a message can erode customer trust, which is crucial for online retailers. The incident also underscores the vulnerabilities associated with third-party platforms and the challenges companies face in securing their entire digital ecosystem. The potential compromise of customer data, even if limited to names and contact details, can lead to further risks like phishing attempts and identity theft, affecting millions of customers globally.
What's Next?
ASOS is continuing its investigation into the unauthorized activity and has taken immediate action to restrict access to the notification platforms. The company has advised customers not to engage with the notification and has stated that its website and app are operating as usual. If personal data was accessed and poses a risk, UK data protection rules generally require notification to the Information Commissioner's Office (ICO) within 72 hours. Cybersecurity experts are urging customers to be cautious of phishing emails and messages that may try to exploit fears surrounding the incident. The company has cyber security insurance, but it is too early to quantify any potential impact on trading. The focus will be on establishing the full extent of the breach and restoring customer confidence.
Beyond the Headlines
The ASOS incident reveals a shift in cyber warfare from behind-the-scenes negotiations to public psychological warfare, directly involving the customer base. This tactic aims to create immediate and intense pressure on companies, forcing a quicker response or payment. It also raises questions about the security of customer messaging systems and the broader implications for digital trust. The incident could prompt other companies to re-evaluate the security protocols for their customer-facing applications and third-party integrations. Furthermore, the public nature of this attack could set a precedent for future cyber extortion attempts, making it more challenging for businesses to manage and mitigate such threats without immediate reputational and financial consequences.








