ASOS customers have received an alarming push notification claiming the online fashion retailer had been hacked, sending the company’s shares sharply lower.
The notification, sent through the ASOS app on Tuesday morning, claimed that the company’s Snowflake cloud environment had been compromised.
It reportedly warned ASOS’s data protection and IT teams to make contact or risk information being leaked.
The message also included a link to a newly created Telegram channel associated with a group calling itself Xuanye.
ASOS shares fall
ASOS shares fell by more than 11% after reports of the apparent cyber incident emerged.
Reuters said ASOS had acknowledged that it was aware of the reports but had not confirmed that a breach had taken place.
The company’s website and app remained accessible following the notification.
ASOS had also not published a statement about the incident on its corporate news page at the time of writing.
Hackers claim Snowflake access
The message sent to customers claimed that the attackers had gained access to ASOS’s Snowflake environment.
Snowflake is a cloud data platform used by companies to store and process large quantities of information.
However, there has been no confirmation from ASOS of what systems, if any, were accessed or whether customer information was compromised.
Reports suggesting that details such as customer measurements, sizes or behavioural information may have been exposed have therefore not yet been verified.
Hundreds report problems
Hundreds of users also reported issues with the ASOS website around the time the notification was sent, although it remains unclear whether those reports were directly connected to the suspected cyber incident.
Cybersecurity firm Sophos told Sky News that it had not previously encountered the Xuanye group and could find no established presence for it in the channels and forums it monitors.
The incident remains under investigation and further information is expected from ASOS.