ASOS has confirmed a data breach after attackers sent unauthorized push notifications through its mobile app, according to BleepingComputer. The notifications claimed that customer data had been stolen from the company's Snowflake environment. The Register also covers the incident, reporting that a rogue notification claimed the Snowflake instance was compromised.
Both sources agree on the basic sequence: the app displayed the rogue notifications, and ASOS acknowledged a breach. They differ in emphasis, however. The Register explicitly states that customer information theft remains unverified, while BleepingComputer frames the data theft as a claim made by the attackers rather than a confirmed outcome.
Neither report provides details on how the notifications were sent or what data, if any, was actually accessed. The incident underscores the risk that cloud data platforms and mobile app delivery channels can become vectors for security scares, even when the underlying theft is not yet proven.