ASOS Confirms Cyberattack After Rogue In-App Notifications
British online retailer ASOS has confirmed a data breach after hackers compromised a third-party communication platform to send unauthorized push notifications to mobile app users.

Unauthorized Notifications Alert ASOS Users
Over the past couple of days, numerous ASOS users in the UK and worldwide complained about receiving unexpected pop-up notifications on their mobile applications titled "ASOS hacked". The unauthorized push alerts began appearing on Tuesday, prompting widespread concern among customers who rely on the fashion retailer's mobile apps for shopping.
The intrusive alerts directly messaged customers via the app, reading: "Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification also directed users toward a newly created Telegram channel operated by a threat actor calling itself the Xuanye Group.
Retailer Confirms Third-Party Platform Breach
In a filing submitted to the London Stock Exchange, the clothing and cosmetics retailer confirmed that its users received unauthorized notifications after a third-party platform utilized for customer communications was hacked. Additional details on the incident were also covered in reports by BleepingComputer and SecurityWeek.
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities,” ASOS stated regarding its ongoing containment response.
Impact on Customer Data and App Security
According to ASOS, basic user information—including names and contact details—may have been accessed during the security incident. However, the online retailer emphasized that it does not believe payment-card information or account passwords were compromised.
The company has pointed out that its official website and application remain unaffected otherwise, and operational activities have not suffered any disruption. ASOS is currently displaying an in-app notice urging customers to disregard the unauthorized alerts and refrain from clicking on any external third-party links contained within them.
Evaluating Claims Involving Snowflake
Although the threat actors claimed via their Telegram channel that they completely compromised a Snowflake instance, ASOS has not publicly confirmed those specific claims, nor has it disclosed the exact identity of the compromised third-party platform.
Security researchers have noted the historical context surrounding data analysis platforms. For instance, campaigns by groups like ShinyHunters have previously targeted Snowflake instances across numerous organizations, though security experts emphasize that initial access vectors for the ASOS incident remain under investigation and unconfirmed.
Extortion Tactics and Industry Reaction
Industry experts highlighted that directly messaging customers through a mobile app is an unusual and deliberate move designed to extract maximum publicity. Security analysts note that leveraging media attention and public awareness is a classic extortion tactic employed by threat groups to pressure victim organizations into negotiations.
As investigations continue, security professionals continue to monitor whether the Xuanye Group's claims hold any merit or represent a broader threat to platforms utilized by enterprise environments.
Sources
- SecurityWeekASOS Confirms Cyberattack, Data Breach
- BleepingComputerASOS confirms data breach after “HACKED” in-app notifications
Continue chronologically




