Unauthorized Activity Detected in Asos App
Asos is investigating a suspicious notification sent to its app users on Tuesday morning that read "ASOS HACKED", which cyber security experts believe was an extortion attempt.

Asos, an online clothing and beauty store, is investigating unauthorized activity involving third-party platforms it uses after its app sent a suspicious notification to users on Tuesday morning.
Dozens of customers reported receiving the notification, which read "ASOS HACKED and was addressed to the company's data protection officer and IT teams. Cyber security experts believe this was an extortion attempt, and some customers even expressed fear about opening the app due to the alarming message.
The notification is thought to have been sent by hackers who may have accessed basic personal information of Asos users during the incident. Asos acknowledged the unauthorized customer notification on Tuesday afternoon, but has yet to confirm exactly how many customers received it.
The company apologized for the incident in an email to customers and assured them that they can shop with confidence while it investigates the matter. However, Asos has not informed the UK's data watchdog, the Information Commission's Office (ICO), about any breach as of yet.
Asos serves around 17 million customers each year across more than 150 markets, making its global footprint substantial. The company's app has been downloaded to android devices over 10 million times, according to Google's Play store.
Some Asos app users in Australia, France, Sweden, and Ireland received an unauthorized notification on Tuesday, according to reports from these countries.
This unusual tactic of hackers informing customers about their potential data breach is rare, as most extortions occur behind closed doors, making this incident a significant moment in cyber-attack history.
The news of the hack sent shockwaves through the market, causing Asos' shares to plummet by around 10% on Tuesday.
Cyber-security experts are warning that while the notification may be alarming, customers should not panic and instead focus on taking necessary precautions to protect their data.
ASOS customers who received a notification about unauthorized access to their accounts are trying to make sense of the message.
Some users were initially confused by the alert, thinking it was an advertisement or a promotion. But as they read on, they realized that something more serious was at play. Analyst Jodie from Edinburgh described her initial reaction: At first I thought it was an ad or a fun promotion like 'ASOS HACKED get 50% off everything for a limited time only'.
The notification has left many customers concerned about the security of their personal data, including bank information and home addresses. Student Erin at the University of Sheffield expressed her worries: My main concern is that my information, such as bank information, home address, telephone number, has been compromised. She also noted that some friends had received similar notifications.
Erin's sister did not receive the notification on the Asos app, raising questions about whether all customers are affected. The student wondered if the lack of a notification meant her data was safe, but she is still uncertain: So the question is what is the extent? Are all customers affected even if they didn't get the notification?
ASOS has responded to the situation by taking immediate action to restrict access to its notification platforms on Tuesday. The company is working with internal and external specialists, as well as relevant authorities, to investigate the incident.
As the investigation into the unauthorized notification sent by hackers to Asos app users continues, it has been confirmed that the National Cyber Security Centre is offering assistance to the company.
Snowflake, a data analytics platform used by dozens of firms including Asos, says its own investigation is ongoing but so far has found no evidence of compromise. However, the company's services have been involved in several high-profile data breaches in recent years, raising questions about their security measures.
According to cybersecurity expert Jen Ellis, Snowflake collects and analyzes data from multiple sources, which could include sensitive information about Asos customers' shopping habits globally. This has led some experts to suggest that the hackers may have accessed more than just the Snowflake database.
Dan Bird, a cybersecurity expert at Horizon3, believes the message sent by the hackers implies they had access to Asos's notification system, which is separate from the Snowflake platform. If both claims are true," he said, "it suggests the attackers got hold of credentials that opened more than one door."
Asos has also released a statement outside of the usual channels, providing an update on the situation to investors and stakeholders. Cybersecurity experts believe those behind the incident are likely trying to apply pressure to Asos to meet their demands rather than targeting its customers directly.
The notification sent by hackers to Asos app users has left many concerned about their personal data security.
However, it's essential to note that receiving this message does not necessarily mean your phone has been compromised in any way.
Asos is yet to disclose the extent of the information that may have been accessed during the incident.
The company's notification advises against clicking on links within the message and instead directs users to visit its official website for updates.
Additionally, customers are warned to be cautious of potential scams that may arise from this situation, including emails, texts, or calls offering refunds, compensation, or assistance with their accounts.
To protect themselves, Asos users should consider using unique passwords across all online services and enabling two-step verification on email and banking accounts.
Facts based on reporting originally published by BBC News Technology.
You may republish this story, in full or in part, if you credit Noti Group and link to it (licence CC BY 4.0). Photos are not included.










