ASOS has confirmed a cybersecurity incident after customers received an unauthorized push notification through the retailer’s own mobile application stating that the company had been hacked and threatening to leak data unless ASOS engaged with the attackers. The notification was sent at around 10 a.m. on October 6 and directed recipients toward a Telegram channel associated with a group calling itself Xuanye Group. ASOS later confirmed that it was investigating unauthorized activity involving third-party platforms used to communicate with customers, restricted access to the affected notification platforms, and began working with internal and external specialists as well as relevant authorities. The company says basic personal information including names and contact details may have been accessed, but it does not currently believe payment-card information or account passwords were affected.
The fact that the attackers were able to push a message directly through ASOS’s legitimate notification channel is particularly significant. This was not merely a social-media claim or a fake website impersonating the retailer. Customers received the message from the application they had already installed and trusted. That turns the communication platform itself into evidence that at least part of ASOS’s customer-messaging infrastructure was being used without authorization. It does not prove that every system claimed by the attackers was compromised, but it does establish that the incident went beyond somebody simply boasting on Telegram.
That distinction matters because trusted communication channels carry inherited credibility. A phishing email from an unfamiliar address can trigger suspicion. A push notification delivered through the official ASOS application receives an entirely different level of trust because the user’s phone, app and notification infrastructure all appear legitimate. Attackers who gain control of that channel no longer need to imitate the brand. They can speak through it.
This creates a broader attack path that can be summarized as: attacker gains unauthorized access to customer-communication platform → legitimate ASOS push infrastructure becomes available → threatening notification delivered through official app → customers are directed toward attacker-controlled Telegram channel → stolen or accessible customer data can potentially support further extortion or phishing.
The incident is therefore as much about communications trust as it is about data exposure.
ASOS has not publicly identified the exact third-party platform that was compromised, nor has it explained how the attackers obtained access. That means it would be premature to describe the incident as an API-key leak, credential theft, OAuth compromise, supply-chain intrusion or exploitation of a software vulnerability. What is confirmed is that one or more third-party platforms used by ASOS to communicate with customers were accessed without authorization.
The attackers themselves claimed they had “fully compromised” an ASOS Snowflake instance. Snowflake, however, says its investigation has found no compromise of the Snowflake platform. That difference is important because an attacker can compromise a customer’s Snowflake account, credentials or surrounding integration without compromising Snowflake’s underlying service. A customer-environment breach and a platform breach are not the same thing.
This is a recurring source of confusion in cloud incidents. If an attacker gains valid credentials to a company’s Snowflake environment, the resulting data theft may involve Snowflake without representing a vulnerability in Snowflake itself. The security question becomes whether the attacker compromised the provider, the customer identity, an integration, or another connected platform. ASOS has not yet disclosed enough technical detail to answer that question.
The same caution applies to the attackers’ data-theft claims. ASOS has confirmed that basic personal information may have been accessed, specifically names and contact details, but has not publicly confirmed the full scope of the data available to the attackers. The group’s claim of broader Snowflake compromise should therefore remain an attacker claim until ASOS or investigators substantiate it.
That said, names and contact information are still useful to criminals, particularly when tied to a well-known retail brand. Attackers can use accurate customer information to create more convincing follow-on phishing campaigns involving fake refunds, order problems, account verification, parcel delivery, payment failures or supposed breach notifications. The psychological advantage comes from combining genuine information with a believable retail context.
A message saying:
“There has been a problem with your ASOS account”
is generic.
A message containing the customer’s correct name, email address and possibly other contextual information immediately appears more credible.
The breach therefore creates a likely secondary social-engineering risk even if passwords and card information were not accessed.
This is why customers should be particularly wary of any message that claims to help them respond to the ASOS breach. High-profile incidents almost always create opportunities for copycat phishing. Criminals can pretend to offer password resets, compensation, refunds or security checks and use the publicity around the real incident as cover.
The safest approach is to navigate directly to the ASOS website or app rather than following links in unsolicited messages.
The malicious push notification itself is a useful reminder that even an official app notification can become untrustworthy if the underlying messaging platform is compromised. Users are often told to trust messages coming from installed applications more than SMS or email. That assumption is generally reasonable, but the ASOS incident demonstrates that trust ultimately depends on the integrity of the infrastructure behind the notification.
Push-notification systems should therefore be treated as privileged communication infrastructure.
A platform capable of sending messages to millions of customers effectively has the ability to speak as the company.
Access to that system deserves controls similar to other high-impact administrative functions:
strong MFA;
least privilege;
short-lived tokens;
restricted API keys;
role separation;
approval for high-volume broadcasts;
anomaly detection;
and detailed audit logging.
An attacker who gains access to the notification platform can potentially do more than send embarrassing messages. They could deliver malicious links, fake security alerts, fraudulent payment instructions or links to credential-harvesting sites directly through the trusted application.
That is why the incident has implications beyond ASOS.
Many organizations use third-party customer-engagement systems for email, SMS, push notifications and personalized campaigns. These platforms often integrate with customer-data systems, analytics platforms and cloud warehouses. From the attacker’s perspective, that makes them attractive because one compromised integration may provide both communication capability and customer context.
The security architecture therefore needs to assume that a communication platform can itself become an attack channel.
One useful control is broadcast anomaly detection. If an account or integration suddenly attempts to send a notification to millions of users, particularly with content or links that differ dramatically from previous campaigns, the platform should require additional validation or approval. A global customer notification is a high-impact action and should not necessarily be possible with the same level of authorization used to send a routine marketing message.
Content-level controls could also help. Notifications containing newly seen external domains, Telegram links, cryptocurrency addresses, threatening language or other high-risk indicators could trigger manual review before distribution.
That may occasionally delay legitimate marketing messages, a tragedy from which civilization would probably recover.
The incident also highlights the importance of third-party identity and token management. Customer-communication platforms are often accessed through API keys, service accounts and OAuth integrations rather than ordinary interactive login. Those machine identities can become invisible attack surfaces because they do not generate the same obvious authentication signals as employees.
Organizations should therefore inventory:
which external platforms can send messages as the company;
which API keys and service accounts control those integrations;
what permissions those identities possess;
where credentials are stored;
how often they rotate;
and whether their usage is behaviorally monitored.
A token that allows a third-party platform to send push notifications to the entire customer base should be treated as a highly privileged credential.
The response should also include reviewing whether attackers gained access only to the notification platform or to the underlying customer-data systems connected to it. ASOS’s acknowledgement that basic personal information may have been accessed suggests the incident was not limited to message delivery. Investigators will need to determine which systems provided that data and whether access extended further than currently confirmed.
This is especially relevant because modern marketing and personalization architectures often connect multiple platforms together. Customer profiles may move between ecommerce systems, CDPs, analytics platforms, data warehouses and engagement tools. A compromise at one point in that chain can expose data from another system even if the underlying provider itself remains secure.
The ASOS incident therefore illustrates a broader integration risk:
retailer → customer-data platform → analytics/data warehouse → messaging platform → mobile app
Attackers do not necessarily need to compromise every component.
They need one sufficiently privileged connection between them.
The attacker’s use of the ASOS app as an extortion channel is also unusual and strategically interesting. Instead of contacting executives privately, they apparently used customer-facing infrastructure to announce the breach publicly and pressure the company. That tactic increases reputational damage immediately and forces the victim to respond under public scrutiny.
In effect, the attackers turned ASOS’s own application into their ransom note.
That creates a different kind of pressure from traditional ransomware or extortion email because customers see the attacker’s message before the organization has completed its own investigation.
It also complicates incident communications. ASOS has to distinguish legitimate corporate notifications from the attacker’s unauthorized message while reassuring users that the app and website remain operational.
ASOS says its website and application are continuing to operate normally, with no current disruption to business operations. That is another useful distinction: this appears primarily to be a data and communications compromise, not an outage or destructive attack.
The market reaction nevertheless shows how quickly cyber incidents can produce business consequences. ASOS shares fell by around 10% after the disclosure, illustrating that customer trust and uncertainty can affect companies even when core systems remain online.
For defenders, the strongest immediate lesson is to treat outbound customer-communication systems as part of the attack surface. Security monitoring tends to focus heavily on inbound threats: malicious email, exploit attempts, credential attacks and malware downloads. The ASOS incident shows why organizations also need visibility into what their own trusted platforms are sending outward.
A sudden unauthorized broadcast may be one of the clearest indicators that a communication platform has been compromised.
Organizations should therefore monitor:
unexpected high-volume push notifications;
new external URLs;
changes to messaging templates;
new administrator or API identities;
unusual geographic access;
unexpected API-token use;
changes in audience targeting;
and notifications sent outside normal campaign workflows.
The investigation should also include revoking and rotating relevant API keys, access tokens and service credentials, not merely changing human passwords.
If compromise occurred through a machine identity, resetting an administrator password may do precisely nothing, which is a lovely way to close an incident ticket while leaving the door open.
The broader attack scenario can currently be summarized conservatively as: unauthorized access to third-party customer-communication platform → attackers gain ability to send push notification through official ASOS app → extortion message sent to customers → attackers claim Snowflake compromise → ASOS restricts platform access → investigation confirms basic customer information may have been accessed → payment cards and passwords currently believed unaffected → investigation continues.
What should not yet be added as confirmed facts are claims that Snowflake itself was breached, that complete customer profiles were stolen, or that payment information and passwords were compromised.
Those claims either remain unverified or have been specifically contradicted by current statements.
The broader security lesson is that customer communication is a privileged capability.
Organizations typically protect payment systems and administrative consoles carefully because they understand the consequences of compromise.
Messaging platforms deserve similar treatment.
If attackers can speak directly to every customer through the official app, they have gained something enormously valuable even before considering whatever data they may also have accessed.
The ASOS incident demonstrates why modern security needs to protect not only the systems that hold customer data, but also the systems that hold customer trust.
Once attackers control either one, the other becomes much easier to exploit.
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
Source: ASOS confirms data breach after “HACKED” in-app notifications via Bleeping Computer — published 06 Oct 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.