“Psychological warfare”: ASOS hackers use push notifications to deliver fear to the front door

"Using the company's app to deliver an extortion message is an aggressive tactic designed to create immediate public pressure."

Share
“Psychological warfare”: ASOS hackers use push notifications to deliver fear to the front door

The British online retailer ASOS has warned that threat actors who sent a malicious push message to customers may have accessed personal data.

At roughly 10 am this morning, ASOS customers received a message on their phones that linked to a Telegram page and said: "We have fully compromised the Snowflake instance. Engage with us, or we will leak it."

The e-commerce giant then announced it was investigating the "unauthorized customer notification" sent using "third-party platforms that we use to communicate with customers".

It wrote: "We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

"Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted."

A public ransom note?

The use of a push notification is a dramatic and "aggressive" tactic designed to create "immediate public, regulatory and market pressure", said Tom Hegel, Distinguished Threat Researcher and Research Lead at SentinelLABS.

However, he questioned whether the hackers really did escape with valuable data.

“The most important distinction right now is between what the attackers claim and what the available evidence establishes," Hegel added.

"The notification indicates that someone was able to abuse a trusted ASOS customer-communications channel, which is serious in its own right, but it does not yet prove the claimed Snowflake compromise or that customer data was stolen."

Boris Cipot, principal security engineer at Black Duck, also advised against trusting the attackers' claims and said: "We don’t yet know whether the claim about Snowflake is real or part of an attempt to create panic and put pressure on ASOS.

"The fact that someone was apparently able to send a message through ASOS’s own app notification channel is certainly concerning, but it doesn’t prove that everything the attackers are saying is true. 

"The ability to send a push notification doesn’t automatically prove access to the data platform the attackers claim to have compromised."

It is not yet known whether the attackers demanded payment - although the push notification is now being compared to a public ransom note.

Charlotte Wilson, head of enterprise for the UK & Ireland at Check Point said: “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note," she continued.

Jamie Moles, Senior Technical Manager at ExtraHop, also argued: “Weaponizing a brand's own infrastructure to send ransom demands directly to customer devices is an aggressive public extortion tactic. Hijacking push notifications leverages millions of customers, bypassing internal IT communication channels to force an instant public response."

Financial and reputational damage

As well as having a dramatic effect on ASOS, the attack is likely to have rattled customers who received the notification,

Marie Wilcox, VP of Market Strategy at Binalyze, said:  "This notification was psychological warfare, designed to whip up panic. Attackers know that any panic piles on the pressure on ASOS to think about paying up rather than taking time to develop a rational response.

 "This is a clear shift in how we see breaches: from learning after the fact, to thousands of users seeing the news pushed onto their phone home screens in real time." 

ASOS shares fell as much as 14% after news of the cyberattack broke, before recovering some of the losses.

Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress, said the damage may not be purely financial.

He warned: "The attackers didn't just steal from ASOS. They used ASOS's own voice to tell its customers about it. That's not just a data breach. That's a complete loss of operational control, and the reputational damage from that alone is significant." 

Snowflake under attack?

Snowflake is a cloud data and AI platform used by thousands of organizations.

In 2024, hackers linked to ShinyHunters, also tracked as UNC5537, compromised Snowflake customer accounts belonging to around 165 organizations, stealing sensitive data that was later used for extortion.

The attackers gained access using customer credentials, many of them previously stolen by infostealer malware.

Daniel dos Santos, VP of research at Forescout, said: "This recent hack may be similar, although it is not confirmed what the initial access was."

The hackers also provided a link to a Telegram channel created today called Xuanye, which also links to a group chat with more than 260 participants.

"Xuanye is not a known threat actor, but the name is of Chinese origin, which could indicate a Chinese-speaking threat actor or simply a false flag,” Daniel dos Santos added.

Compromising trust

The incident highlights a wider shift towards attackers abusing trusted accounts, tokens and integrations rather than breaking in through traditional exploits.

Mick Leach, Field CISO at Abnormal AI, said: "The detail that matters here is the delivery channel. If the attackers pushed a message to customers through ASOS's own app, they were operating from inside a trusted system.

"We don't yet know whether that came from a compromised account, a stolen credential or token, or something else, and ASOS hasn't confirmed the attackers' claim.

"But it fits a pattern we've seen for years: attackers log in with access that looks legitimate rather than break in."

Rebecca Moody, Head of Data Research at Comparitech, said the incident also echoes a similar attack in the Netherlands, where hackers called the LPG Group contacted customers of a grocery chain. The threat actors asked them to pay €10 each to have their stolen data deleted after the company refused to pay the group's $270,000 ransom demand.

And in South Africa, a tech company paid The Gentlemen to delete stolen data, only for the group to start contacting its clients to try and secure a ransom from them, too.

Moody said: "Hackers are increasingly targeting individuals after breaching a company. In a number of instances, customers have been contacted to try and put pressure on the breached entity and/or seek a ransom from them.

"Retailers remain a key target for hackers. Our Q3 ransomware report shows that attacks on the retail sector have increased by 29 percent from Q2 2026 and by nearly 100 percent when compared to the same period last year (Q3 2025)."

Follow Machine on LinkedIn