Shoppers expecting discount codes from online fashion giant ASOS woke up to a digital extortion note instead.
On Oct. 6, ASOS customers received an unauthorized push notification through the retailer’s official mobile app declaring “ASOS HACKED.” Addressed directly to the retailer's data protection officer and IT teams, the message warned: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The rogue alert directed the company to a Telegram channel run by a group calling itself the Xuanye Group.
The company confirmed that an unauthorized notification was distributed through third-party platforms used to communicate with shoppers. The company said it immediately restricted access to the notification platforms and is working with internal and external specialist advisers and relevant authorities.
ASOS acknowledged that “basic personal information including name and contact details may have been accessed,” but emphasized that it does not “believe that payment-card information or account passwords were impacted.”
ASOS confirmed that an unauthorized notification was distributed through third-party platforms used to communicate with shoppers. Image: Reddit
Anatomy of an aggressive hijack
The intrusion represents a severe operational breakdown that goes beyond standard backend theft. Snowflake told the BBC that its ongoing investigation has found “no compromise” of its own platform. ASOS confirmed unauthorized activity involving third-party communication platforms, but the entry point remains unclear and the attackers’ claim of access to its Snowflake instance is unverified.
“It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant,” Pieter Arntz, senior malware intelligence researcher at Malwarebytes, told eSecurity Planet (eSP). “ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access.”
The most important detail may not be the disputed Snowflake claim but the attackers’ ability to reach customers through ASOS’ legitimate communication channel.
In a comment to eSP, Arctic Wolf’s regional vice president of solutions engineering, Nick Dyer, pointed out the psychological leverage of the attack vector.
“Having a notification like this pop up on your phone is unusual and alarming, and sadly it's a result of security breaches, which could involve sensitive customer data becoming a regular experience,” Dyer told eSP.
Dyer noted that attackers appeared to be using the notification to create panic and pressure ASOS into paying a ransom. That creates a security problem beyond the initial intrusion: customers may now struggle to distinguish legitimate retailer communications from attacker-controlled messages. For businesses, securing customer-facing notification systems therefore needs to be treated as part of the security boundary, rather than merely a marketing function.
Protecting your account
ASOS has advised customers to disregard the push alert and avoid opening any third-party links it contained. The company says it does not believe payment-card information or account passwords were affected. Customers should nevertheless watch for phishing attempts that exploit concern about the incident.
Dyer urged customers not to click or interact with unexpected notifications, emails or messages claiming to be from ASOS, especially those asking them to click links or provide personal details. He also advised watching for calls or texts from unknown numbers that push urgency, and going directly to the ASOS website instead. The UK’s National Cyber Security Centre advises all ASOS customers to assume they may be affected, even if they did not receive the notification. Customers should watch for suspicious messages, use strong, unique passwords and enable two-step verification wherever available.
Read more: The BigCommerce third-party app breach shows how compromised integrations can expose retailer customer data even when the core platform remains secure.





