Data Breaches

ASOS App Alert Turned Extortion Channel

ASOS and the UK NCSC are investigating a cyber incident after some customers received an unauthorized “ASOS HACKED” push notification on Tuesday that claimed a Snowflake compromise. ASOS says names and contact details may have been accessed, while it does not believe payment card data or account passwords were affected.

The message appears to have come through ASOS’s own app, which made the threat look like an official company notice instead of an outside ransom note. That matters because the notification itself became the attack: it could speak with ASOS’s authority to every user who saw it, whether or not the backend theft claim is verified.

For retailers that use mobile apps to reach customers, the customer-messaging path is now part of the incident surface. If that channel is hijacked, it can trigger immediate panic, reputational damage, and market reaction even before investigators settle what, if anything, was taken from the underlying systems.

4 sources · 6h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: ASOS App Alert Turned Extortion Channel

More from today