Hackers used the ASOS app to send customers a ransom demand

Hackers appear to have gained access to ASOS’s push notification system and used the retailer’s own app to send customers a ransom demand.
Customers of the British online fashion retailer received a notification titled “ASOS HACKED” on Tuesday morning. The message directed the company to contact the attackers through Telegram and threatened to leak its data.
The link led to a Telegram channel apparently operated by a group calling itself Xuanye. According to The Guardian, the group had not previously surfaced in hacker forums or other Telegram channels. The publication noted that the unusually public message may have been an attempt to attract attention.
“Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance,” the message read.
Snowflake is a cloud platform used to store, process and analyze data. For retailers, that can include transactions and customer information such as clothing sizes and body measurements. It remains unclear what ASOS stores in the allegedly compromised environment or whether the attackers obtained any of that data.
The notification itself indicates that the attackers gained access to at least part of the infrastructure ASOS uses to communicate with customers. It is not yet clear how they obtained that access or whether it was connected to the claimed Snowflake breach.
ASOS said it was aware of the incident and was investigating but has not confirmed that its systems or customer data were compromised. The incident could also lead to follow-up phishing attempts, including messages impersonating ASOS and asking customers to reset passwords, confirm payment details or check orders.