Asos is investigating unauthorised access to third-party platforms it uses to communicate with customers, after shoppers received a push notification sent by a party claiming to have compromised its data. The notification told Asos's data protection officer and IT staff that the company's Snowflake instance had been fully compromised, and directed recipients to a Telegram channel, The Guardian reported.
The online fashion retailer said it does not believe payment card records or account passwords were compromised. Its website and app continued to operate normally with no disruption to operations, though Asos shares fell more than 14% during the trading day before closing down 9.56%. Asos moved to cut off access to the notification platforms after the incident came to light and confirmed it is working with internal and external specialist advisers and relevant authorities.
The notification reached Asos app users beyond the UK, with recipients reported in Australia, France, Sweden and the Republic of Ireland. According to Google's Play Store, Android devices account for more than 10 million downloads of the Asos app.
The group behind the notification has named itself the Xuanye Group, and its Telegram channel posted that payment information is not affected and the app is safe to use. The channel indicated that customer information would not be touched for a designated period.
Snowflake is a cloud platform whose functions include storing, processing and analysing data such as transactions and demographic details including clothing sizes and body measurements, and it supports push notifications to phones. Dan Bird from Horizon3 told the BBC that delivering a push notification requires access to a notification system that sits apart from the Snowflake platform, and that if both claimed access points are confirmed, the attackers likely held credentials covering multiple systems. Snowflake's services have previously been linked to cyber incidents affecting Ticketmaster and Santander.
Dray Agha, senior manager of security operations at Huntress, described the tactic of sending a ransom demand to consumer devices as aggressive and designed to push the business into rapid negotiation, and advised shoppers to be alert to targeted phishing attempts. Marijus Briedis, chief technology officer at NordVPN, said high-profile cyber incidents create conditions suited to phishing, with criminals likely to send messages impersonating Asos and asking customers to reset passwords, confirm payment details, check orders or claim refunds. Sophos added that the Xuanye Group had not been mentioned previously on hacker forums or other Telegram channels.
Asos apologised to customers for the unauthorised push notification and urged them not to click or engage with the external link it contained. The National Cyber Security Centre offered assistance to Asos.
The company announced it holds cybersecurity cover, including business continuity insurance, through a large global provider, though it described quantifying any potential effect on trading as premature. Asos's customer base spans more than 150 markets, with roughly 17 million customers served annually.
Asos customers' basic personal information, including names and contact details, may have been accessed, though Asos says payment card details and passwords are not believed to be affected. Security experts advise customers to avoid clicking links in the notification, stay alert to scam emails, texts or calls purporting to be from Asos, use distinct passwords across services, turn on two-step verification for email and banking, and watch online transactions for anything unusual.
Reporting: The Guardian, BBC
Written by Pick & Scroll News from the reporting and documents linked above.

