ASOS confirms data breach after hackers push 'HACKED' alert through its app
UK fashion retailer ASOS confirmed customers' names and contact details may have been exposed after attackers used its app to send an extortion message.
At a glance
- On October 6, ASOS app users received an unauthorized push notification titled 'ASOS HACKED' claiming a compromise of the company's Snowflake instance.
- ASOS said names and contact details may have been exposed, but it does not believe payment card data or account passwords were affected.
- A previously unknown group calling itself Xuanye claimed responsibility on Telegram without providing evidence.
- According to The Record, ASOS shares fell more than 10% on the day.
British online fashion retailer ASOS has confirmed a data breach after attackers abused its third-party communication platforms to send an unauthorized push notification to mobile app users on Tuesday, October 6, 2026. According to BleepingComputer, the company said basic personal information such as names and contact details may have been exposed, while it does not believe payment card information or account passwords were affected. The incident matters because the attackers effectively turned a major retailer's own app into a channel for their extortion demand, reaching customers directly.
What happened
BleepingComputer reports that the notifications began appearing around 5:00 a.m. ET on Tuesday and reached numerous app users. The message, titled "ASOS HACKED", was addressed to the company's data protection officer and IT team and claimed that the attackers had "fully compromised the Snowflake instance", threatening to leak data unless ASOS engaged with them.
According to The Record, the message directed users to a Telegram channel claiming to represent Xuanye Group, a previously unknown cyber extortion group. In a Telegram post cited by BleepingComputer, the group said the app was safe to use and that the incident involved customer information held on its servers. The Record adds that the group claimed customer data would not be released for a "designated period". Neither outlet reported any evidence supporting these claims, and ASOS has not confirmed whether its Snowflake environment was actually compromised.
Company response and market impact
ASOS displayed an in-app warning telling customers to disregard the unauthorized alert and not to click the external link, BleepingComputer said. According to The Record, the company's regulatory statement said it is investigating its third-party communication platforms, has restricted access to affected systems, and has engaged specialist advisers and the relevant authorities. The website and app continued to operate normally.
The Record reports that ASOS shares fell more than 10% on Tuesday. Check Point executive Charlotte Wilson told the publication the attack was "deeply serious", noting how quickly investors reacted before full details of the incident emerged.
ASOS has not disclosed how many customers were affected.
Who is affected
Based on the company's statement, ASOS customers whose names and contact details are stored by the retailer may be impacted. Because the exact scope has not been published, it is not yet clear whether all customers or only a subset are involved.
What to do
ASOS customers should not interact with the link included in the unauthorized notification and should be cautious about emails, SMS messages or calls that reference the incident, since exposed contact details are commonly used for follow-up phishing. Although ASOS does not believe passwords were affected, users who reuse their ASOS password elsewhere may still choose to change it and enable additional account protections where available. Organizations using third-party push notification and customer engagement platforms should review who holds credentials to these services, enforce multi-factor authentication and monitor for unusual message campaigns.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



