decrypted · 7 october 2026 · ransomware and cybercrime · vulnerabilities and patching · surveillance and privacy

ASOS's own app became the ransom note: who can speak in your name?

At about 10am on Tuesday, ASOS customers received a push notification headed "ASOS HACKED". It was addressed not to them but to the retailer's data protection officer and IT team, and it claimed the sender had "fully compromised the Snowflake instance". ASOS shares fell by more than 10% that day. The alarming part is not the claim, which remains unproven. It is the channel it arrived through: the one customers trust most.

What happened, and what is only claimed

The message went out through ASOS's own app and linked to a Telegram channel run by a previously unknown extortion group calling itself Xuanye Group. ASOS confirmed that an unauthorised customer notification was sent and said it was investigating "unauthorised activity involving third-party platforms that we use to communicate with customers".

Read those words beside the attackers' boast. The group named Snowflake, which is a data warehouse. ASOS named a customer messaging platform. They are different systems, and the group has so far offered no evidence that it holds any data. Until someone shows otherwise, the Snowflake line is a claim.

ASOS also said basic personal information, including names and contact details, may have been accessed, and that payment card details and account passwords were not believed to be affected. That is an initial assessment, not a final one. It follows a separate incident disclosed in August, reported as involving compromised credentials and customer account access. Nobody has publicly linked the two.

The tannoy problem

Picture a shop's tannoy. Whoever holds the microphone does not need the stockroom keys to cause a panic. They only need to reach the microphone. A push notification system is that microphone, with a twist: it speaks from the phone's home screen, with the retailer's name on it, to everyone who installed the app.

Even if no database was touched, the attacker obtained what extortion needs most, which is an audience delivered by the victim. The same threat on a million lock screens is a share-price event, a regulatory problem and a phishing opportunity, because customers now expect odd messages from the brand.

The Secure by Design lesson

The design question is not "is our database safe?" but "who can speak in our name?" It usually includes a marketing platform, an email service, an SMS gateway and a mobile messaging tool, each run by a supplier, each reachable with a login or an API key.

For a UK director, five questions are worth asking this week:

None of this is expensive. A second approver adds minutes to a campaign. Key rotation is a calendar entry. What is costly is discovering, in front of customers, that nobody owned the microphone.

Also this week

Atlassian: this morning's flaw is now under attack. Since our earlier post on CVE-2026-21589, Previdian reported exploitation attempts against its honeypots within two hours of a public proof-of-concept appearing, with 15 attempts from three IP addresses, according to BleepingComputer and The Hacker News. The flaw is unauthenticated file access in Data Center products including Confluence, Jira and Bitbucket. Where Crowd is in use, the reported chain reaches plaintext credentials and administrator accounts. The Hacker News rates it 9.3 on the CVSS scale and lists fixes including Confluence 9.2.26 and 10.2.19. The advice stands: patch, and until you have, keep these systems off the internet. The lesson is speed. Once details are public, the gap between disclosure and attack is measured in hours, so your patch process must be too.

Google pauses its open-source bounty as AI noise grows. BleepingComputer reports that Google has suspended submissions to its Open Source Software Vulnerability Rewards Program, citing a rise in automated submissions, "the vast majority of which are not valid". The programme launched in August 2022 and covers Google-maintained projects such as Golang, Angular and Protocol Buffers, with an update promised in the first quarter of 2027. In March, Google had already said it would stop accepting AI-generated submissions and demand stronger proof, according to CSO Online. For UK organisations the point is quiet but real: open-source maintainers are the ones triaging this flood, and the software your business runs depends on their attention. If you build on open source, funding or contributing to it is now a security control, not charity.

Sources

Not sure who can send messages to your customers in your name? get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.