WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

The ASOS incident: When attackers use the channels customers trust

Network switches with status lights in a dark server rackAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers.

The attackers’ wider claims remain unverified, and Snowflake told Sky News that its investigation had found no compromise of the Snowflake platform at that point. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram.

The company also said basic personal information, including names and contact details, may have been accessed, while payment-card information and account passwords were not believed to be affected. When the message comes from the real app Most security awareness advice assumes there will be something suspicious for the recipient to notice.

Sources & evidence