ASOS app users receive push notifications apparently sent by hackers
Source Entity
BBC News

ASOS app users have reported receiving suspicious push notifications from hackers claiming a compromise of a Snowflake data instance. This incident follows a pattern of high-profile security breaches involving the Snowflake platform.
Analysis of the ASOS Security Notification Incident
The Breach Incident
Recently, numerous ASOS mobile application users reported receiving highly unusual push notifications that appeared to originate from the company's internal systems. Rather than standard marketing updates, these messages contained claims of a security compromise, specifically alleging that the hackers had "fully compromised the Snowflake instance." The fact that these notifications were pushed directly to customer devices suggests a significant breach of the application's communication infrastructure, raising immediate concerns about the integrity of the platform's user-facing channels.
Targeting the Data Infrastructure
While the notifications were delivered to end-users, the content was explicitly addressed to the ASOS Data Protection Officer (DPO) and the IT department. This unusual communication strategy serves as a form of digital extortion or a "proof of life" demonstration by the attackers. By bypassing traditional email channels and using the company’s own app to deliver the message, the perpetrators intended to force a public response from the company’s leadership, thereby escalating the pressure on the IT security teams to acknowledge a potential data vulnerability.
The Snowflake Connection
Central to this incident is the reference to Snowflake, a prominent cloud-based data storage and analytics company. Snowflake provides the backend infrastructure for a vast array of global enterprises to manage their data pipelines. While it remains unconfirmed if ASOS directly utilizes Snowflake for its operations, the mention of the platform suggests the attackers are leveraging the reputation of this specific vendor to validate their claims. The association is particularly alarming given that Snowflake has recently been linked to high-profile security incidents involving major corporations like Ticketmaster and Santander.
Patterns in Modern Cyber-Extortion
This event highlights a concerning trend in modern cybercrime: the weaponization of third-party service provider vulnerabilities. When a primary vendor like Snowflake experiences security issues, the ripple effect on downstream clients can be catastrophic. The fact that hackers are now using these breaches to send direct push notifications to consumer devices indicates a shift toward more aggressive, public-facing extortion tactics designed to maximize brand damage and force rapid corporate disclosure.
Broader Security Implications
For users, this incident underscores the fragility of the digital ecosystem. Even if a company like ASOS maintains robust internal security, their reliance on third-party SaaS (Software as a Service) providers means they are only as secure as their weakest link. As businesses continue to migrate data to centralized cloud environments, the importance of robust API security and push-notification authentication becomes paramount to prevent unauthorized actors from hijacking communication channels to deliver malicious or alarmist content.
Future Trends and Outlook
Moving forward, we can expect to see an increase in "notification hijacking" as a tactic for cybercriminals. Companies will need to implement stricter access controls over their mobile marketing platforms to ensure that only verified administrative accounts can push notifications to their user base. Furthermore, this incident will likely trigger a wave of forensic audits across the retail sector, as businesses scramble to verify their own security posture in relation to their data storage partners to mitigate potential reputational and regulatory fallout.