$ techbeacon▋
Breaches

ASOS Investigates Mobile App Exploit After Hackers Send Fake Notifications Claiming Snowflake Leak

ASOS Investigates Mobile App Exploit After Hackers Send Fake Notifications Claiming Snowflake Leak

British fashion e‑commerce platform ASOS said on Tuesday it is probing a breach in which unauthorized actors used the company’s official mobile application to push deceptive notifications to users. The messages, which appeared to originate from ASOS, warned recipients of a supposed data exposure involving Snowflake, the cloud‑based data‑warehousing service that many retailers rely on for analytics.

According to the initial report, the malicious notifications were delivered through the app’s push‑notification system, a channel typically reserved for order updates, promotions and security alerts. Recipients were prompted to click a link that led to a phishing site designed to harvest login credentials. ASOS confirmed that it had not authorized the messages and that the incident was under active investigation by its security team and external experts.

ASOS, which reported revenues of over £3.5 billion in its last fiscal year, has previously emphasized its commitment to safeguarding customer data. The retailer noted that the breach appears to be limited to the notification service and that there is no evidence at this stage that personal information, such as payment details or addresses, was accessed. Nonetheless, the company urged users to remain vigilant, avoid clicking on unsolicited links, and to update passwords if they suspect any compromise.

The incident highlights the growing trend of attackers targeting mobile app infrastructure to amplify phishing campaigns. By exploiting legitimate notification channels, malicious actors can bypass many traditional security filters, as the messages are delivered through trusted platforms. Security analysts point out that the use of Snowflake in the fraudulent claim is likely a tactic to lend credibility, given the service’s prominence in the retail sector.

ASOS said it is working with Snowflake to confirm that no breach of the data‑warehousing service occurred and to rule out any unauthorized access to its own analytics environment. The retailer also indicated that it will review its push‑notification architecture and consider additional safeguards, such as multi‑factor authentication for administrative access and tighter monitoring of outbound messages. The investigation remains ongoing, and further updates are expected as more details emerge.

Source: Hackread
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related