Skip to main content

A ransom note sent through ASOS’s own app, and what it does and doesn’t prove

0
Medium
Published: 10/07/2026 (10/07/2026, 23:19:59 UTC)
Source: Reddit Cybersecurity

Description

On 6 October 2026, attackers sent an unauthorized ransom note via ASOS's own app notification system, claiming to have compromised ASOS's Snowflake data platform and threatening to leak data unless paid. ASOS confirmed the unauthorized notification and restricted access to its messaging platforms, acknowledging that names and contact details may have been accessed, but payment information was not affected. The attackers used third-party platforms ASOS employs for customer communication. The incident follows a similar prior attack on Betterment, where rogue messages led to data leaks. ASOS is investigating the breach, but no proof of Snowflake compromise has been provided, and Snowflake denies platform compromise. Customers are advised to assume they are affected and be cautious of follow-on fraud and phishing attempts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 06:48:21 UTC

Technical Analysis

Attackers exploited third-party messaging platforms used by ASOS to send an unauthorized push notification to ASOS app users, delivering an extortion demand claiming full compromise of ASOS's Snowflake instance. The attackers' communication channels were active before the notification, indicating premeditated public pressure. ASOS confirmed the unauthorized notification and restricted access to its notification platforms, stating that names and contact details may have been accessed, but payment information and passwords were not believed to be affected. Snowflake denied any compromise of its platform. The attackers have not provided data samples or proof of access. This incident resembles a prior attack on Betterment, where unauthorized messages preceded data leaks. ASOS customers face increased risk of phishing and fraud due to exposed contact data and credential lists circulating on criminal forums.

Potential Impact

ASOS customers may have had their names and contact details accessed, increasing the risk of targeted phishing and fraud. Payment card information and passwords are not believed to be affected. The unauthorized notification caused reputational damage and public concern. The incident demonstrates that attackers can misuse third-party communication platforms to reach customers directly. There is no confirmed data leak or proof of Snowflake compromise at this time. The incident may lead to follow-on fraud attempts leveraging the exposed contact information and previously leaked credentials.

Defensive Guidance

ASOS has restricted access to its notification platforms and is investigating the incident. Customers are advised to disregard the unauthorized notification and not to follow any links it contained. The UK National Cyber Security Centre (NCSC) recommends that all ASOS customers assume they are affected and exercise caution against phishing attempts. No further immediate action is required from customers beyond vigilance. Organizations should ensure strong identity controls on systems that can message customers, similar to payment system controls, to prevent misuse.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ac73caf2cdf04f656f30e2d

Added to database: 10/08/2026, 06:48:15 UTC

Last enriched: 10/08/2026, 06:48:21 UTC

Last updated: 10/09/2026, 04:48:07 UTC

Views: 23

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses