A ransom note sent through ASOS’s own app, and what it does and doesn’t prove
Description
On 6 October 2026, attackers sent an unauthorized ransom note via ASOS's own app notification system, claiming to have compromised ASOS's Snowflake data platform and threatening to leak data unless paid. ASOS confirmed the unauthorized notification and restricted access to its messaging platforms, acknowledging that names and contact details may have been accessed, but payment information was not affected. The attackers used third-party platforms ASOS employs for customer communication. The incident follows a similar prior attack on Betterment, where rogue messages led to data leaks. ASOS is investigating the breach, but no proof of Snowflake compromise has been provided, and Snowflake denies platform compromise. Customers are advised to assume they are affected and be cautious of follow-on fraud and phishing attempts.
Reddit Discussion
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Attackers exploited third-party messaging platforms used by ASOS to send an unauthorized push notification to ASOS app users, delivering an extortion demand claiming full compromise of ASOS's Snowflake instance. The attackers' communication channels were active before the notification, indicating premeditated public pressure. ASOS confirmed the unauthorized notification and restricted access to its notification platforms, stating that names and contact details may have been accessed, but payment information and passwords were not believed to be affected. Snowflake denied any compromise of its platform. The attackers have not provided data samples or proof of access. This incident resembles a prior attack on Betterment, where unauthorized messages preceded data leaks. ASOS customers face increased risk of phishing and fraud due to exposed contact data and credential lists circulating on criminal forums.
Potential Impact
ASOS customers may have had their names and contact details accessed, increasing the risk of targeted phishing and fraud. Payment card information and passwords are not believed to be affected. The unauthorized notification caused reputational damage and public concern. The incident demonstrates that attackers can misuse third-party communication platforms to reach customers directly. There is no confirmed data leak or proof of Snowflake compromise at this time. The incident may lead to follow-on fraud attempts leveraging the exposed contact information and previously leaked credentials.
Defensive Guidance
ASOS has restricted access to its notification platforms and is investigating the incident. Customers are advised to disregard the unauthorized notification and not to follow any links it contained. The UK National Cyber Security Centre (NCSC) recommends that all ASOS customers assume they are affected and exercise caution against phishing attempts. No further immediate action is required from customers beyond vigilance. Organizations should ensure strong identity controls on systems that can message customers, similar to payment system controls, to prevent misuse.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ac73caf2cdf04f656f30e2d
Added to database: 10/08/2026, 06:48:15 UTC
Last enriched: 10/08/2026, 06:48:21 UTC
Last updated: 10/09/2026, 04:48:07 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.