ASOS App Notification: What We Know and What Remains Unclear

Written by Caine Glancy

Following the threatening notification sent to ASOS customers, this article explores what is known, what remains unconfirmed and why organisations should separate claims from confirmed facts.

ASOS App Notification: What We Know and What Remains Unclear

Getting a notification through an app like ASOS seems like fairly standard practice, whether it’s informing you about new deals on that jacket you’re eyeing up or reminding you about its current offers and deals but I’d bet you wouldn’t expect that notification to announce that ASOS had been hacked. The issue with this news piece now is that whilst this notification is alarming it does not, by itself, show what systems or data may have been compromised.

ASOS customers received a notification through the retailer’s app on 6 October saying the company had been “hacked”. The notification itself has currently been described as fraudulent by a customer service representative. A report by Sky News said the message claimed an attacker had compromised a Snowflake instance and threatened to leak information.

At this point, the notification and the claims in it do not establish what happened beyond the message being sent through the app. The extent of any risk, and whether any data or systems were affected, remains unclear.

What does the notification tell us?

It tells us that customers received a threatening message through a channel they would normally associate with ASOS. It does not confirm the attacker’s claims or establish whether personal data was accessed, although in this instance it does seem incredibly likely.

During a developing incident of this size, organisations and customers need to know what is confirmed, what is being investigated and what remains unknown. Treating an unverified claim as fact could mislead people and that will be the last thing ASOS will want to do but dismissing it without evidence could also leave them unprepared.

What remains unknown?

The information available at this point does not establish what systems or accounts may have been affected, whether personal data was accessed or taken, or what risk there may be to customers. Until more information is available, the claims in the notification should be treated as unconfirmed. The risk cannot be assessed from the notification alone.

What should organisations connected to ASOS do?

There is no specific action for organisations generally based on the notification alone. However, any organisation that uses ASOS as a supplier should stay alert for further information and carry out its own fact-finding as details emerge.

That means checking whether any data it shared with ASOS could be affected, using reliable information as it becomes available. The notification by itself does not show that supplier data has been affected.

Trust depends on clear updates

A threatening message through a familiar app can create uncertainty, even when the message itself is described as fraudulent. In this case, the available information does not yet show the extent of any risk or what, if anything, was compromised.

As more information becomes available, updates should distinguish confirmed facts from claims that remain under investigation. For organisations with a supplier relationship, careful fact-finding can help establish whether their own data may be affected.

One thing I would recommend is that people steer away from making a purchase at this point in time until we know more about the scope and severity of this incident.

Need support with data protection or cyber security? Contact Data Protection People to discuss how we can help.