
A privacy expert has explained a little more about the alarming ASOS notification which shoppers received earlier today and what customers should absolutely avoid doing.
The push notification, which was sent to ASOS app users earlier this morning (6 October), read: "ASOS HACKED.
"Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
DPO stands for data protection officer - the person appointed by a company to oversee the protection of customers’ personal information while Snowflake is a cloud-based data platform used by a wide range of companies.
Advert
The alarming alert also included a link to a Telegram chat.
Shares in the company tumbled by more than 10% on Tuesday morning as a result.
A privacy expert has shared her advice regarding the alarming ASOS 'hacking' message app shoppers received this morning (Cheng Xin / Contributor / Getty Images)

ASOS has now said it is investigating 'unauthorised activity involving third-party platforms' used to communicate with its customers, whose basic personal details may have been accessed, adding: "We do not believe that payment-card information or account passwords were impacted."
Laura Tyrylyte, privacy advocate at NordVPN, has since shared her advice to any ASOS users out there who are left feeling understandably rattled from this morning's incident.
She explained: "The attackers aren't just claiming to have breached ASOS; they're publicly pressuring the company to engage with them, or they'll leak what they say they've taken."
The expert also highlighted that what stands out about the message is how that threat reached people.
"A message written for ASOS's data protection and IT teams went straight to customers' phones through the company's own app," the expert outlined.
"Shoppers were pulled into an extortion attempt they had nothing to do with, and that's a real breach of trust regardless of what the investigation finds."

Tyrylyte continued: "The attackers say they have 'fully compromised' ASOS's Snowflake instance.
"Snowflake is a cloud platform companies use to store and analyse large amounts of customer information.
"If that claim holds up, the question becomes what was in there."
She warned that retail data warehouses often hold 'far more' than people expect, from order history and addresses to clothing sizes, adding: "None of that is information you can easily change once it's out.
"That said, customers shouldn't assume their personal or payment details have been stolen. Nothing has been established yet."
According to Tyrylyte, what people should watch for is 'what comes next'.
"Big cyber incidents are perfect cover for phishing. Criminals will send emails and texts posing as ASOS, asking you to reset a password, confirm payment details, check an order or claim a refund," she said. "Don't click links in unexpected messages, even convincing ones.
"Open the ASOS app or type the website address yourself. And make sure your ASOS password is unique. If you've used it anywhere else, change it there too."

Cyber expert Rob Demain, chief executive of e2e-assure, said it was unclear if the claimed Snowflake hack was real, 'because we only have the attacker’s word for it'.
He said via PA: "The concerning thing for customers is that they received the threat through a channel they already trusted.
"While unconfirmed, one possibility is that the compromise is confined to the customer engagement or marketing systems connected to Asos.
"If the attackers only accessed that layer, it could explain the app notifications, but doesn’t prove any access to the wider retail infrastructure or the claimed data theft.
"The architecture of how ASOS connects to customer data illustrates the wider risk – marketing systems connect valuable customer information with the ability to send messages under the retailer’s name."
The LADbible Media Group has previously reached out to ASOS for comment.
Topics: ASOS, Social Media, Technology, Fashion, Shopping