Hackers sent an extortion threat directly to ASOS customers through the retailer’s official app on Tuesday, October 6, apparently to pressure the company into paying, according to Proton. Customers received a push notification threatening to leak data unless ASOS engaged with the attackers. ASOS told customers that names and contact information might have been accessed, while passwords and payment information did not appear affected.
The demand addressed ASOS’s data protection officer and IT department, even though customers were the people receiving it. Proton interprets that choice as an effort to make the threat public and increase pressure for a payment. According to Proton, ASOS shares dropped as much as 11% after the attack, with customers expressing concern on social media.
Proton says the attackers gained entry through an employee account on Simon AI, a platform connected to Snowflake, which ASOS used for cloud data storage and analysis. Its account cites news reports that the employee was deceived into handing over login credentials by someone posing as a trusted contact. Despite the hackers’ claim about compromising a Snowflake instance, Proton says Snowflake itself was not compromised in this attack.
ASOS said in a market statement on October 6 that it was examining unauthorized activity on services used for customer communications, according to Proton. In the days afterward, Proton says reports indicated that information concerning potentially millions of customers had been collected. The attackers supplied the BBC with a sample that included dates of birth and customer numbers, alongside addresses, telephone numbers, email addresses and names.
Proton warns that stolen personal details could help attackers make subsequent phishing attempts more convincing to ASOS customers. It advises customers to set a fresh, strong password and report suspicious approaches through ASOS’s official customer care channel. Customers should also open a retailer’s website or app themselves when signing in, instead of following unexpected links, Proton advises.
In a September 29 security post, Proton described how attackers combine public clues, including employee roles and references to business software, to prepare believable impersonation attempts. Its October 8 post about stolen credentials described passwords being resold or tried on other services before a business discovers the exposure. For businesses facing attacks like the ASOS incident, Proton recommends limiting employee access to customer messaging systems and requiring two-factor authentication on those accounts.













