ASOS Customers Received A “Hacked” Alert In Their App – What Should Businesses Do When Attackers Go Public?

On 6 October, ASOS customers didn’t get a notification about autumn knitwear. They got an alarming message reading “ASOS HACKED”.

It addressed the retailer’s data protection officer and IT team directly, claimed the attackers had “fully compromised the Snowflake instance” and warned that they’d leak it unless the company engaged with them.

The real twist here is the execution. Instead of lurking in the shadows while demanding a payout, the hackers flipped the script by turning the retailer’s marketing channels against it. They pinged customers across the UK, Australia, Ireland and France with the news. ASOS says it is examining a security breach across its third-party customer messaging apps and has rushed to restrict access.

We know the alert went out and the messaging platforms were breached, but everything else remains murky. ASOS hasn’t confirmed the Snowflake connection, and Snowflake itself maintains its systems are clean while checks continue. The retailer maintains that while names and contact information might have leaked, passwords and card details are still secure.

 

When The Claim Lands Before The Facts

 

That’s the dilemma for any business in this position. The incident is public, customers are asking questions and the team still doesn’t know what was taken, if anything. An attacker’s claim is evidence of an incident or an attempted extortion, but it isn’t proof that a database was accessed or that data was stolen.

The first hours tend to be about damage control over transparency: stopping more unauthorised messages, restricting accounts and integrations, and preserving logs before anything is reset. The UK National Cyber Security Centre advises keeping a strict paper trail, centralising incident records and keeping external messaging sharp and coordinated.

Then comes the communication. Say too little and a company looks evasive, say too much and it risks confirming a breach that forensics can’t later support. Under UK rules, firms have 72 hours to notify the Information Commissioner’s Office if a breach threatens personal data, and the regulator is clear that you do not need every single fact nailed down before ringing the alarm.

The Snowflake claim also raises a question for anyone storing customer data in one cloud platform. These platforms aren’t inherently unsafe, but they concentrate a lot of valuable information behind a small number of identities and integrations, and attackers know it. A claim like this could suggest stolen credentials, a missing multi-factor login or an exposed token, or it could simply be exaggerated, and which one it is shapes the whole response.

So we asked incident response, cloud security and breach communication specialists what a business should do in the first 24 hours when an attack goes public before it’s confirmed, and what this says about holding customer data on cloud platforms.

 

 

Our Experts:

 

  • Scott Neve, Founder, Ops Intel
  • Peter Moorhead, CTO, Amicis Group
  • Dray Agha, Senior Manager of Security Operations, Huntress
  • Rebecca Leversidge, Head of Group Marketing, Premierline
  • Vitaly Simonovich, Senior AI Security Researcher, Cato Networks
  • Avi Dayan, VP of Incident Response, Sygnia
  • Anna Webb, Global Director, Security and Identity Support Services, Kocho
  • Spencer Young, SVP International, Delinea
  • Xavi Sheikrojan, Senior Risk Intelligence Manager, Signifyd
  • Andy Ward, SVP International, Absolute Security

 

Scott Neve, Founder, Ops Intel

 

Scott Neve, Founder, Ops Intel

 

“The first 24 hours of a public-but-unconfirmed incident are a legal clock as much as a technical one, and most businesses only find that out on the day.
“Under UK GDPR, a firm has 72 hours from becoming aware of a personal data breach to report it to the ICO, unless it is unlikely to put people at risk.

“Aware” means a reasonable degree of certainty that personal data has been compromised. A public claim from attackers does not start that clock by itself, but it does start the investigation that will, so the first job is to establish fast whether customer data actually left the building. A firm that waits for certainty before it starts looking is the one that misses the deadline.

“In practice, day one looks like this: open a written incident log with timestamps from the first alert, because the regulator will ask when you knew and what you did. Decide who speaks publicly, and say only what you can stand behind. Check what your cloud contract says your provider must tell you, and how fast. And be ready to tell customers directly if the risk to them is high, because that is a separate duty, not a courtesy.

“On cloud: the platform rarely loses the data on its own. It is usually access, a stolen login or a key with too much reach. Holding data in the cloud does not move the responsibility for it. The business that collected the data still owns the duty to protect it and to report it.”

 

Peter Moorhead, CTO, Amicis Group

 

Peter Moorhead, CTO, Amicis Group

 

“The first thing a business must do is assume the attack has compromised systems while concurrently establishing the facts. To avoid worst case scenarios, such as significant data loss and mission critical outages, response and remediation must begin immediately.

“Isolate systems at the network level to prevent lateral movement of attackers and ensure that credentials are rotated so compromised identities cannot be used to gain further access to data and additional systems.

“The ASOS incident adds a further dimension, as the attackers used trusted channels to direct customers to suspicious Telegram groups, adding significant confusion and reputational risk to the attack. This will have required a coordinated response across security, legal and communications teams, with oversight from senior executives.

“Despite the damage already caused, the incident should not be interpreted as evidence that cloud platforms themselves are inherently unsafe. It all comes back to the tools and processes that organisations use to manage access to their systems, whether these are cloud environments or on-premise systems.

“Compromised credentials, excessive privileges or poorly controlled third-party access will leave plenty of openings for adversaries to pass through. This is why continuous visibility of who and what can access sensitive data and strong identity controls must be prioritised.”

 

Dray Agha, Senior Manager of Security Operations, Huntress

 

Dray Agha, Senior Manager of Security Operations, Huntress

 

“Attackers weaponise public panic to force a quick payout. Businesses must regain control through calm, transparent updates while incident response teams verify the blast radius. As the cyber criminals have already brought this into the public forum, immediately issue a public holding statement to curb panic, while instantly locking down compromised channels (like push notifications) and isolating targeted databases.

“The objective of post-compromise strategic communication should be reputation assurance. Businesses can recover hardware, data, and costs via insurance. Their reputation, however, can take years to recover, if at all, if comms are mishandled.

“Cloud warehouses centralise massive volumes of customer data. While the underlying infrastructure is highly secure, the sheer scale of the data makes them prime targets for extortionists. But in reality, the cloud is not really a ‘unique’ facet of this intrusion or ASOS network – most businesses nowadays have mixtures of platforms that comprise their business.

“What we see at Huntress, however, is that many businesses do not secure their cloud assets with the same rigour as on-prem. There’s no insight yet if ASOS falls into this trend or bucks it.”

 

Rebecca Leversidge, Head of Group Marketing, Premierline

 

Rebecca Leversidge, Head of Group Marketing, Premierline

 

“When a cyber incident plays out publicly in real time, the first 24 hours require swift, structured action: immediately isolate potential entry points, rotate credentials, mobilise forensic and legal advisors and communicate transparently to prevent panic, even while facts are still being established.

“What the ASOS situation highlights is the fundamental risk of cloud platforms like Snowflake. While cloud infrastructure offers enterprise-grade scalability, it consolidates sensitive assets into high-value target environments. Storing customer data on third-party cloud systems never outsources your liability; the business remains fully accountable.

“Cybercriminals are increasingly hijacking internal customer-facing channels, like push notifications, to force public extortion. To mitigate this, robust data governance, strict multi-factor authentication and continuous monitoring must be backed by a strong cyber insurance policy to absorb the inevitable financial and reputational shock.”

 

Vitaly Simonovich, Senior AI Security Researcher, Cato Networks

 

Vitaly Simonovich, Senior AI Security Researcher, Cato Networks

 

“Sending an extortion demand through ASOS’s own app directly to customers appears calculated to put public pressure on the company. The message addresses the DPO and IT team, but its audience is the customer base: it uses a trusted communication channel to amplify concern and demand attention.

“Using customers to pressure a victim organisation is an established extortion tactic; the unusual feature here is the apparent use of ASOS’s own push notifications to deliver it. The Telegram link provides a route to the group, but does not establish that negotiations are underway. ASOS faces immediate public pressure while the claimed Snowflake compromise and any theft of customer data remain unverified.”

 

Avi Dayan, VP of Incident Response, Sygnia

 

Avi Dayan, VP of Incident Response, Sygnia

 

 

“The cyber incident at ASOS, where attackers utilised the official app to send push notifications to users, represents a significant evolution in the extortion tactics of threat groups. Instead of negotiating behind closed doors, attackers are employing psychological warfare and leveraging the customer base to create direct, public pressure on management and the Data Protection Officer (DPO).

“Simultaneously, the claim of a complete compromise of the Snowflake instance illustrates the level of risk facing cloud-based data lakes, which centralise massive amounts of business data and private customer information.

“Ahead of the November holiday shopping season, retail and e-commerce organisations must re-evaluate third-party access privileges to their most sensitive databases, implement strict access controls and prepare for response scenarios that require rapid synchronisation between technological containment and public crisis management.”

 

Anna Webb, Global Director, Security and Identity Support Services, Kocho

 

Anna Webb, Global Director, Security and Identity Support Services, Kocho

 

“Today’s incident involving ASOS is particularly concerning because of the level of access the attackers have achieved. The group has claimed to have compromised ASOS’s Snowflake environment, while some customers have also received an extortion message through the retailer’s app. If confirmed, that would suggest the attackers were potentially able to reach more than one part of the organisation’s technology environment.

“The critical question in an incident like this is not simply whether a credential has been compromised, but how much authority that identity has and what other systems it can reach. Privileged access can accumulate over time across employees, third parties, service accounts and applications, creating connections that attackers can exploit. Organisations therefore need to understand and govern those access paths, remove unnecessary standing privileges and continuously review who and what has access to critical systems. The aim should be to ensure that compromising one identity does not provide a route into multiple parts of the business.”

 

Spencer Young, SVP International, Delinea

 

Spencer Young, SVP International, Delinea

 

“In other recent, high-profile attacks on retailers, there’s been a common denominator: cyber criminals logging in using stolen and misused credentials, rather than breaking in. Crucially, that access often comes from third-party retail supply chains, rather than the end target itself.

“The retail industry responded phenomenally well to last year’s attacks, turning those lessons into stronger oversight of supply chains and tighter access controls.

“But this morning’s ASOS attack shows that cybercrime is relentless. The priority now is to maintain that momentum by continuously verifying access and ensuring every employee, supplier and system has only the permissions it genuinely needs.”

 

Xavi Sheikrojan, Senior Risk Intelligence Manager, Signifyd

 

Xavi Sheikrojan, Senior Risk Intelligence Manager, Signifyd

 

“Account takeover is already one of the fastest-growing threats facing retailers. Signifyd data shows account takeover fraud pressure across EMEA has increased 82% year on year by GMV, with $73 million in attempted account takeover fraud blocked across the region in the last 12 months.

“That is why breaches involving customer information matter beyond the immediate incident. Once personal data is exposed, fraudsters can combine it with credentials obtained elsewhere and use credential-stuffing attacks to try to gain access to legitimate customer accounts.

“For retailers, that creates a particularly difficult challenge because the fraudster is no longer necessarily presenting as an unknown or obviously suspicious shopper. They can be operating through an established account, using genuine customer information and behaviour designed to resemble the legitimate account holder.

“It is too early to attribute any increase in account takeover directly to the ASOS breach, but retailers should expect exposed data to be tested. Following a breach, monitoring for changes in login behaviour, account details, devices, delivery information and purchasing patterns becomes critical to identifying when a genuine customer account may have fallen into the wrong hands.”

 

Andy Ward, SVP International, Absolute Security

 

Andy Ward, SVP International, Absolute Security

 

“It only takes one successful cyberattack or data breach for thousands, if not millions, of people to be put at risk. With the rise of AI, these threats are not only becoming smarter but faster, and it is inevitable that other UK businesses will face a threat at some point.

“It is essential that UK businesses are prioritising cyber resilience to minimise disruption and potential downtime. With threats evolving faster than ever, organisations must implement real-time visibility into their IT environments to identify vulnerabilities and respond to these incidents when they occur.”