Users of the Asos shopping app across the UK received a startling push notification that appears to have been sent by attackers, claiming full compromise of a "Snowflake instance" and demanding engagement or threatening to leak data. The message was addressed to Asos's data protection officer and IT team and showed up directly on customers' phones; numerous screenshots circulated on social media and at least one BBC newsroom phone captured the alert. Cybersecurity commentators note that sending an app push implies access to Asos's notification system as well as whatever credentials control the claimed Snowflake environment, suggesting the attackers may have obtained multiple sets of credentials rather than only accessing a single cloud datastore.
Snowflake is a cloud-based data platform used by thousands of companies to store and analyse data; it has been implicated in other high-profile incidents linked to breaches affecting services such as Ticketmaster and Santander. Asos has not confirmed whether it uses Snowflake or what, if any, customer data might be stored there. Security experts emphasize the unusual public exposure of an alleged extortion demand, since most negotiations take place privately, and investigators will be looking for evidence of lateral access beyond the named database and how the attackers triggered the in-app notification.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.