ASOS customers received an unauthorized push notification sent through ASOS’s real mobile app. The message claimed ASOS’s Snowflake environment was compromised and urged recipients to contact the sender via Telegram, leveraging the trust people place in official app notifications. ASOS said it was investigating activity involving third-party customer-communication platforms and warned that names and contact details may have been accessed.
How the attack worked
Customers of ASOS received a push notification delivered through the retailer's own official mobile app, a channel they already trusted. The message claimed that ASOS's Snowflake environment had been compromised and directed recipients to engage with the sender through Telegram. ASOS later confirmed to media that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers.
The pretext relied on urgency and brand trust: a legitimate app notification telling customers to move the conversation to an unrelated chat platform to resolve a supposed security issue. This is a red flag pattern defenders should recognize, since legitimate support processes rarely ask customers to switch to apps like Telegram.
Why it succeeded
Most security awareness advice assumes there will be something suspicious for a recipient to notice, such as a spoofed sender address or an unfamiliar domain. Those checks become far less useful when the message arrives through the genuine app already sitting on someone's phone. Because the notification channel itself was authentic, customers had little reason to question its legitimacy before being redirected elsewhere.
This incident also illustrates a broader risk: a legitimate account, integration, or SaaS platform used in an unexpected way can provide access to attackers while generating activity that looks relatively ordinary when viewed on its own. ASOS said the activity involved third-party platforms used for customer communications, which can make misuse harder to distinguish from normal business operations.
What to watch for
- A trusted brand notification that redirects you to an unrelated chat app to resolve a security issue
- Urgent breach language without the normal in-app support steps
- Requests to communicate outside official, known support channels
- Follow-on messages referencing the original incident, such as fake refund offers, password reset prompts, or account security checks
Building resistance
Organizations and individuals can reduce exposure by treating the authenticity of a channel as separate from the legitimacy of its content. Even a message arriving through a verified app should be checked against official support pages or known contact methods before any action is taken, especially one that proposes moving the conversation elsewhere.
Teams managing third-party customer-communication tools should review permissions, integrations, and authentication controls regularly, since misuse of these platforms may not stand out from routine activity. Security awareness programs should also prepare stakeholders for a second wave of risk: once a real incident becomes public, a phishing email or text offering an account update, refund, password reset, or security check immediately has a credible event behind it, making it more convincing than typical phishing attempts.
Key findings
- Attackers delivered an unauthorized push notification through ASOS’s own app, exploiting an already-trusted channel.
- The push notification claimed a Snowflake compromise and directed recipients to engage via Telegram.
- ASOS said it was investigating activity involving third-party customer-communication platforms.
- ASOS warned that basic personal information (names and contact details) may have been accessed, but passwords and payment cards were not believed to be affected.
- Snowflake stated it had not found evidence of a Snowflake platform compromise at the time.
- The incident could enable follow-on scams (emails/texts) that reference the real event to appear more credible.
Who’s being targeted
- Commonly targeted roles: Security awareness, Customer support / contact center, Marketing / CRM teams (owners of customer messaging platforms), IT / Identity & Access Management, Incident response / SOC.
- Affected industries: Retail / e-commerce, Consumer mobile apps, Third-party customer communications / marketing platforms.
- Attack channels: website, telegram.
- Impersonated: ASOS (via the official ASOS app notification channel).
Red flags to watch for
- A legitimate brand notification redirects you to an unrelated chat app (Telegram) to resolve a security issue
- High-pressure breach language without normal in-app support steps
- Unexpected request to communicate outside official support channels
Frequently asked questions
What happened in the ASOS push notification incident?
ASOS customers received an unauthorized push notification through the company's own app claiming its Snowflake environment had been compromised and directing recipients to engage with the sender via Telegram.
Was ASOS customer data compromised?
ASOS said names and contact details may have been accessed, but passwords and payment cards were not believed to be affected, and it was investigating activity involving third-party customer-communication platforms.
Did Snowflake confirm a breach?
Snowflake stated it had not found evidence of a Snowflake platform compromise at the time.
Why is this incident concerning beyond the initial notification?
The incident could enable follow-on scams, such as emails or texts referencing the real event to appear more credible, including fake refund, password reset, or security check requests.
Read the video transcript
Imagine unlocking your phone and your ASOS app pops up: “Our Snowflake data was hacked. Message us on Telegram, now.” That actually happened. A hostile push went out through ASOS’s real app, abusing a trusted channel and telling customers to move the conversation to Telegram about a supposed Snowflake breach. Here’s the twist: Snowflake said they saw no compromise, and ASOS later confirmed it was an unauthorized notification via third-party messaging tools. The real danger is the second wave: emails or texts about refunds or password resets that name this exact incident to feel legit. If any app claims a breach and tells you to switch to Telegram, WhatsApp, or similar, stop. Close the message and go to the official website or in-app help yourself to check what’s real.