ASOS Customers Get Odd 'Hacked' Alert as Snowflake Compromise Is Claimed
Customers of online fashion retailer ASOS received an unusual push notification on October 6 that appeared to come from the company's own app. The message was addressed to ASOS's data protection officer and IT team, claimed the attackers had "fully compromised the Snowflake instance", and demanded the company engage with them or face a data leak. It was signed 'xuanyewengateway' and included a link to a Telegram channel. ASOS has not confirmed any compromise at the time of publication.
Snowflake is a cloud-based data platform that companies use to store, manage, analyse and share large volumes of data. Attackers often target it. The most recent large-scale known incident, in May 2024, involved criminals using credentials stolen by infostealer malware to log into customer Snowflake accounts that did not have multifactor authentication (MFA) enforced. The source also notes that Wiz researchers found a critical script injection vulnerability in one of Snowflake's public GitHub repositories.
Jake Moore, global cybersecurity advisor at ESET, said that sending a push notification suggests the attackers have reached at least some connected ASOS systems, but it does not prove their claims about the scale of any data theft. He believes the attackers are likely broadcasting the claim to pressure ASOS and set up a ransom demand. If confirmed, he warned, it could be one of the most visible hacks in history.