deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

ASOS app users receive extortion push notifications from apparent hackers

ASOS customers received extortion messages pushed through the retailer's own app, with a newly formed group claiming to have compromised a Snowflake instance.

ASOS app users receive extortion push notifications from apparent hackers

Shoppers turned into messengers

Dozens of ASOS customers have posted on social media about a puzzling pop-up that arrived through the fashion retailer's official app, according to the BBC. The message was not a marketing ploy or a delivery update: it appears to have been an extortion demand sent by criminals who found a way to use ASOS's own notification system.

Although the notification landed on customers' phones, it was not written for them. The BBC reports that the text is aimed at the retailer's data protection officer and its IT staff, meaning shoppers were effectively used as a delivery channel for a ransom-style message intended for the company itself.

A claim centred on Snowflake

The message asserts that the attackers have "fully compromised the Snowflake instance", the BBC says. Snowflake supplies cloud-based data warehousing and analytics tools used by many large organisations. The report highlights two significant unknowns: it is not confirmed whether ASOS is even a Snowflake customer, and there is no clarity on what data, if any, might be stored with the service.

Snowflake's name has surfaced in several prominent security incidents in recent years, and the company has been linked to breaches affecting Ticketmaster and Santander.

A very public extortion attempt

The BBC describes the approach as highly unusual. Cybercrime extortion is normally conducted behind closed doors, with attackers calculating that a victim will pay quietly to avoid publicity. By pushing the demand to app users, whoever is behind this message inverted that logic, maximising embarrassment and pressure instead.

The notification contained a link to a Telegram channel run by a group calling itself Xuanye Group. According to the BBC, the channel was created on the same day the messages went out, carries just three posts, and its most recent entry concerns the ASOS incident — early signals of a brand-new operation rather than an established crew.

What the access implies

Dan Bird of cyber security firm Horizon3, quoted by the BBC, points to a detail that may matter more than the Snowflake claim itself. Delivering a push notification to ASOS app users would require control of the retailer's notification infrastructure, which sits separately from any Snowflake data platform.

If both claims prove accurate, Bird suggests, the attackers would have obtained credentials reaching more than one part of ASOS's technology stack — pointing to a broader intrusion than a single compromised database would explain.

Why it matters

Nothing in the BBC's reporting confirms that customer data has actually been stolen, and ASOS's relationship with Snowflake remains unverified. Even so, the incident stands out for two reasons.

First, hijacking a push notification system is itself a serious compromise. Push channels are trusted by default: messages arrive through the official app and users are conditioned to treat them as legitimate. An attacker who controls that channel holds a direct line to customers' phones, something that could be abused for phishing at scale.

Second, the tactic signals a shift in extortion strategy. Rather than negotiating privately, attackers are weaponising a company's own customer relationships as leverage. For any organisation running a consumer app, the episode is a reminder that notification infrastructure deserves the same security scrutiny as the databases behind it — and for users, that even a message from a trusted app can warrant scepticism when it urges a click.

  • #security
  • #data-breach
  • #extortion
  • #snowflake
  • #e-commerce

Related posts