Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 07, 2026 · 9 min read

ASOS Data Breach: Hackers Sent 'HACKED' App Notifications

At around 10am on Tuesday, October 6, 2026, ASOS app users received a push alert written by extortionists. ASOS confirms the notification was unauthorised, says it is investigating unauthorised activity involving the third party platforms it uses to message customers, and says names and contact details may have been accessed. The attackers' Snowflake claim remains unproven.

The alert landed on lock screens under the ASOS name, in the slot where sale reminders and delivery updates normally appear. "ASOS HACKED," it read, according to BleepingComputer. "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." DPO is short for data protection officer.

It was a ransom note, and ASOS's own app delivered it. Hours later the company told the stock market it was investigating unauthorised activity involving the tools it uses to talk to shoppers. For anyone with an ASOS account, the practical question is what arrives in the inbox next.

Key Takeaways

  • ASOS told the London Stock Exchange that "at around 10am" on October 6, 2026, "an unauthorised customer notification was sent to ASOS customers."
  • ASOS says "basic personal information including name and contact details may have been accessed" and that it does not believe payment card information or account passwords were impacted.
  • Xuanye Group, a name extortion trackers had not seen before, claimed the attack on Telegram and published no sample of stolen data.
  • Snowflake says it has "found no compromise of the Snowflake platform," and ASOS has neither confirmed the Snowflake claim nor said how many customers are affected.
  • The NCSC, the UK's cyber security agency, says ASOS customers "should assume you are affected by this incident, even if you did not receive the unauthorised notification."
A hand holding a smartphone on a commuter train with a blurred notification banner on the lock screen and shopping parcels on the next seat

What Happened to ASOS on October 6?

Attackers used ASOS's own push notification system to broadcast an extortion message. BleepingComputer says the alerts began at approximately 5:00 a.m. ET, which is 10am in London, and that reports on Reddit indicated the message "reached many, if not all, mobile app users."

The alert pointed to a Telegram channel run by a group calling itself Xuanye Group. The Record called it "a name not previously seen by experts who track cyber extortion groups" and noted that such crews "typically contact companies privately" before going public.

The market moved first. The Guardian reported that ASOS shares dived more than 14% during the day and closed down 9.56%. The company's regulatory statement came late on Tuesday afternoon, per The Record. ASOS also apologised to customers directly, in wording the Guardian quoted:"We're sorry that you may have received an unauthorised push notification from us earlier today. Please disregard the notification and do not click or engage with the external third-party link it contained."

What Has ASOS Confirmed, and What Is Only Claimed?

ASOS has confirmed the rogue notification, says it is investigating unauthorised activity involving the third party platforms it uses to message customers, and says names and contact details may have been accessed. Everything about Snowflake comes from the attackers alone.

Confirmed in ASOS's statement to the London Stock Exchange:

  • "We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers."
  • "We took immediate action to restrict access to the notification platforms."
  • "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted."

Claimed by Xuanye Group, without evidence:

  • That it "fully compromised the Snowflake instance."
  • That "the incident involves customer information, it is safe on our server, and it will not be touched for a designated period."
  • That payment information is not affected.

The Record found that the channel "contained no samples of customer data or other material that independently supported the group's claims."

Unknown: how many people are affected, which platforms were accessed and how the attackers got in. ASOS's statement says it has 16.5m active customers in over 100 markets. That is the size of its customer base, not a victim count.

Did Hackers Really Breach ASOS's Snowflake Data?

Nobody outside the attackers has confirmed it. A Snowflake spokesperson told Infosecurity Magazine: "At this time, we can report that we have found no compromise of the Snowflake platform."

That sentence and the attackers' claim can both be true. In 2024, criminals raided Snowflake data belonging to at least 165 customers without breaking Snowflake itself. They logged in to customer tenants with stolen credentials, as we covered when the hacker behind that spree pleaded guilty. A clean platform says nothing about one customer's tenant, or about a marketing tool plugged into it.

One researcher has pointed at a possible bridge. Pieter Arntz of Malwarebytes, quoted by Infosecurity Magazine, noted that ASOS uses Simon AI for marketing and that the tool runs on Snowflake. Nobody has said that platform was the one accessed, and ASOS has named no vendor. Arntz himself cautioned: "the connection alone doesn't establish what attackers could actually access."

Why Is a Hijacked Messaging Platform So Dangerous?

Whoever controls it speaks in the brand's voice, in the one place customers have been trained to trust. A push alert from the ASOS app has no sender address to inspect and no link to hover over. It simply appears under the ASOS icon.

We saw the email version in September, when attackers took over Brevo accounts and sent a fake Trezor security alert to roughly 347,000 real subscribers. The difference is intent. The Brevo attackers wanted readers to click. Xuanye Group wanted ASOS to panic, and used its customers as the audience.

That leaves ASOS with an awkward instruction. Its fix for a malicious ASOS notification was to tell customers to disregard an ASOS notification. Every genuine alert it sends this month, including any breach notice, now arrives with a question mark.

The Pressure Play: Extortion Through a Victim's Own Channels

Going public through a victim's own equipment is an old trick with a new delivery method.

  • November 2020: the Egregor ransomware gang hit retail group Cencosud, and ransom notes came out of store receipt printers. BleepingComputer wrote that the gang prints them "to increase public awareness of the attack and pressure a victim into paying."
  • April 2021: Krebs on Security documented the Clop gang emailing a victim's customers. A RaceTrac rewards member got a message saying the company had been hacked and urging: "Call or write to this store and ask to protect your privacy!!!!"

The ASOS alert merges both moves: the company's own machinery, pointed at its own customers. Check Point's Charlotte Wilson, quoted by The Record, said that if confirmed the hackers appeared to have "turned ASOS's own app into their ransom note."

Most coverage has skipped a second pattern. On August 21, 2026, ASOS US wrote to customers about accounts entered "using login credentials obtained from a source outside ASOS," activity it detected on July 28. That description fits passwords stolen or reused elsewhere, a weakness on the customer's side. Ten weeks later to the day, the unauthorised activity is in platforms ASOS itself selected. Nothing published connects the two.

Why Email Users Should Care: ASOS Phishing Comes Next

The realistic harm from this breach arrives by email and text, not through the ASOS app. A name plus contact details is all a mass phishing run needs, and the headlines hand scammers a ready story. NordVPN's Marijus Briedis, quoted by the Guardian, said:"Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund."

First, you do not need to be in the stolen data to be targeted. With 16.5m active customers, a scammer can spray "ASOS security alert" emails at any list and reach plenty of real shoppers. Second, the data does not expire. Free Mobile customers in France were still getting phishing emails that copy the carrier's real templates in September 2026, two years after 24 million subscriber contracts were stolen.

The NCSC's alert on the ASOS incident says the same: "Look out for suspicious messages, which can arrive some time after a data breach incident." The real ASOS will be emailing too. If it has to notify affected customers, that notice lands in the same inbox as the fakes. Treat both identically: read it, click nothing, then open the app or type asos.com yourself.

What Does UK GDPR Require From ASOS Now?

UK GDPR gives ASOS 72 hours to report a notifiable breach to the Information Commissioner's Office, and requires it to tell customers directly if the risk to them is high. The ICO's breach guidance is blunt: "You must report a notifiable breach to the ICO without undue delay, but not later than 72 hours after becoming aware of it."

ASOS's own statement times the push at around 10am on Tuesday. If that was the moment it became aware, the deadline falls at around 10am on Friday, October 9, and sooner if it knew earlier. ASOS says it is working with "all relevant authorities" but names none. We found no ICO comment in any coverage we reviewed, so whether a report has been filed is not public.

Telling individuals carries a higher bar. Where a breach is "likely to result in a high risk to the rights and freedoms of individuals," the ICO says "you must inform those concerned directly and without undue delay." A vendor is no shield: a processor that suffers a breach must tell the controller, and the controller reports.

Here the attackers got there first. ASOS customers heard about the incident from the criminals, hours before the company's statement. Compliance teams should study that sequence. An incident plan that assumes you control the timing of disclosure fails once an intruder holds your notification tool.

What Should ASOS Customers Do Right Now?

Assume you are affected, as the NCSC advises, and act before the first fake email arrives.

  1. Ignore the push alert and its link. Do not open the Telegram channel or message the people behind it. That is ASOS's own instruction.
  2. Never follow a link in an ASOS email or text. Refunds, held orders and password resets can all be checked by opening the app or typing asos.com.
  3. Change your ASOS password if you use it anywhere else. ASOS says passwords were not impacted, but the July incident used logins obtained outside ASOS. The NCSC recommends "passkeys, or strong, separate passwords plus two-step verification."
  4. Report the fakes. In the UK, forward suspicious emails to report@phishing.gov.uk, as the NCSC explains, and forward scam texts to 7726 for free. In the US, the FTC also says to forward spam texts to 7726.

Security teams have a short audit to run. List everyone who can send from your push, email and SMS tools, and check that those logins sit behind multifactor authentication. Then time how fast you could revoke every API key. ASOS had to restrict access to its notification platforms while the market watched.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.