Shoppers using the ASOS app have received a push notification claiming the online retailer has been "fully compromised", prompting some customers to delete their saved payment details. ASOS has yet to release a statement, and it is currently unclear if any data has been affected.
Message sent via push notification
The alert, titled "ASOS HACKED", was sent on Tuesday and read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification included a link that appears to point to the messaging app Telegram, suggesting the senders are inviting ASOS to engage with them.
DPO stands for data protection officer, the person appointed by a company to oversee the protection and security of customer information. Snowflake is a cloud-based data platform used by a wide range of businesses.
Customers react and take precautions
Many customers have shared online that they believe the message may be a marketing strategy to promote the site's 60% off sale, which has been running for a number of days.
Since 9.30am on Tuesday, October 6, hundreds of customers in the UK have reported an issue with the app to Downdetector. Customers have begun deleting their saved payment details to prevent them from being stolen by potential hackers. The online website and app seem to be unaffected.