ASOS App Users Targeted in Unusual Public Ransomware Extortion Attempt
Cybersecurity experts are investigating a potential breach involving ASOS after users across the UK received alarming pop-up messages via the retailer’s app apparently sent by hackers. The notifications, addressed to ASOS’s data protection officer (DPO) and IT team, demanded engagement or threatened to leak compromised data, specifically referencing Snowflake, a cloud-based data storage and analytics provider linked to multiple high-profile breaches in recent years.
The message read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” Dozens of users reported receiving the alert, which stands out for its public nature most ransomware negotiations occur privately to avoid reputational damage and encourage discreet payouts. Charlotte Wilson, head of enterprise at Check Point, called the tactic “deeply serious,” noting the audacity of hijacking ASOS’s own app to deliver the ransom note.
It remains unclear whether ASOS is a Snowflake customer or what data, if any, may have been exposed. The company has not yet responded to requests for comment. The incident highlights growing concerns over third-party data storage vulnerabilities, as attackers increasingly exploit weaknesses in widely used platforms to target multiple organizations. Further details on the breach’s scope and impact are expected as the investigation continues.
Source: https://www.bbc.com/news/articles/cj62ylzpr6d3o
ASOS TPRM report: https://www.rankiteo.com/company/asos-com
Snowflake TPRM report: https://www.rankiteo.com/company/snowflake-computing
"id": "snoaso1791282235",
"linkid": "snowflake-computing, asos-com",
"type": "Ransomware",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Dozens of users (reported)',
'industry': 'E-commerce/Fashion',
'location': 'UK',
'name': 'ASOS',
'type': 'Retailer'}],
'attack_vector': 'Compromised third-party cloud service (Snowflake)',
'data_breach': {'data_exfiltration': 'Threatened data leak'},
'description': 'Cybersecurity experts are investigating a potential breach '
'involving ASOS after users across the UK received alarming '
'pop-up messages via the retailer’s app apparently sent by '
'hackers. The notifications demanded engagement or threatened '
'to leak compromised data, specifically referencing Snowflake, '
'a cloud-based data storage and analytics provider linked to '
'multiple high-profile breaches in recent years.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'public ransom note',
'data_compromised': 'Potentially compromised data (unspecified)',
'systems_affected': 'ASOS app'},
'initial_access_broker': {'entry_point': 'Snowflake instance'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion',
'ransomware': {'data_exfiltration': 'Threatened',
'ransom_demanded': 'Engagement with threat actors'},
'references': [{'source': 'Check Point (Charlotte Wilson, Head of '
'Enterprise)'}],
'title': 'ASOS App Users Targeted in Unusual Public Ransomware Extortion '
'Attempt',
'type': 'Ransomware Extortion',
'vulnerability_exploited': 'Third-party data storage vulnerabilities'}