ASOS and Snowflake: ASOS app users receive push notifications apparently sent by hackers

ASOS and Snowflake: ASOS app users receive push notifications apparently sent by hackers

ASOS App Users Targeted in Unusual Public Ransomware Extortion Attempt

Cybersecurity experts are investigating a potential breach involving ASOS after users across the UK received alarming pop-up messages via the retailer’s app apparently sent by hackers. The notifications, addressed to ASOS’s data protection officer (DPO) and IT team, demanded engagement or threatened to leak compromised data, specifically referencing Snowflake, a cloud-based data storage and analytics provider linked to multiple high-profile breaches in recent years.

The message read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” Dozens of users reported receiving the alert, which stands out for its public nature most ransomware negotiations occur privately to avoid reputational damage and encourage discreet payouts. Charlotte Wilson, head of enterprise at Check Point, called the tactic “deeply serious,” noting the audacity of hijacking ASOS’s own app to deliver the ransom note.

It remains unclear whether ASOS is a Snowflake customer or what data, if any, may have been exposed. The company has not yet responded to requests for comment. The incident highlights growing concerns over third-party data storage vulnerabilities, as attackers increasingly exploit weaknesses in widely used platforms to target multiple organizations. Further details on the breach’s scope and impact are expected as the investigation continues.

Source: https://www.bbc.com/news/articles/cj62ylzpr6d3o

ASOS TPRM report: https://www.rankiteo.com/company/asos-com

Snowflake TPRM report: https://www.rankiteo.com/company/snowflake-computing

"id": "snoaso1791282235",
"linkid": "snowflake-computing, asos-com",
"type": "Ransomware",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Dozens of users (reported)',
                        'industry': 'E-commerce/Fashion',
                        'location': 'UK',
                        'name': 'ASOS',
                        'type': 'Retailer'}],
 'attack_vector': 'Compromised third-party cloud service (Snowflake)',
 'data_breach': {'data_exfiltration': 'Threatened data leak'},
 'description': 'Cybersecurity experts are investigating a potential breach '
                'involving ASOS after users across the UK received alarming '
                'pop-up messages via the retailer’s app apparently sent by '
                'hackers. The notifications demanded engagement or threatened '
                'to leak compromised data, specifically referencing Snowflake, '
                'a cloud-based data storage and analytics provider linked to '
                'multiple high-profile breaches in recent years.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'public ransom note',
            'data_compromised': 'Potentially compromised data (unspecified)',
            'systems_affected': 'ASOS app'},
 'initial_access_broker': {'entry_point': 'Snowflake instance'},
 'investigation_status': 'Ongoing',
 'motivation': 'Extortion',
 'ransomware': {'data_exfiltration': 'Threatened',
                'ransom_demanded': 'Engagement with threat actors'},
 'references': [{'source': 'Check Point (Charlotte Wilson, Head of '
                           'Enterprise)'}],
 'title': 'ASOS App Users Targeted in Unusual Public Ransomware Extortion '
          'Attempt',
 'type': 'Ransomware Extortion',
 'vulnerability_exploited': 'Third-party data storage vulnerabilities'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.