MikhbarMIKHBAR
Cybersecurity

ASOS Confirms Cyberattack After Rogue In-App Notifications

British online retailer ASOS has confirmed a data breach after hackers compromised a third-party communication platform to send unauthorized push notifications to mobile app users.

ASOS Confirms Cyberattack After Rogue In-App Notifications

Unauthorized Notifications Alert ASOS Users

Over the past couple of days, numerous ASOS users in the UK and worldwide complained about receiving unexpected pop-up notifications on their mobile applications titled "ASOS hacked". The unauthorized push alerts began appearing on Tuesday, prompting widespread concern among customers who rely on the fashion retailer's mobile apps for shopping.

The intrusive alerts directly messaged customers via the app, reading: "Dear ASOS DPO [data protection officer] and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification also directed users toward a newly created Telegram channel operated by a threat actor calling itself the Xuanye Group.

Retailer Confirms Third-Party Platform Breach

In a filing submitted to the London Stock Exchange, the clothing and cosmetics retailer confirmed that its users received unauthorized notifications after a third-party platform utilized for customer communications was hacked. Additional details on the incident were also covered in reports by BleepingComputer and SecurityWeek.

“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities,” ASOS stated regarding its ongoing containment response.

Impact on Customer Data and App Security

According to ASOS, basic user information—including names and contact details—may have been accessed during the security incident. However, the online retailer emphasized that it does not believe payment-card information or account passwords were compromised.

The company has pointed out that its official website and application remain unaffected otherwise, and operational activities have not suffered any disruption. ASOS is currently displaying an in-app notice urging customers to disregard the unauthorized alerts and refrain from clicking on any external third-party links contained within them.

Evaluating Claims Involving Snowflake

Although the threat actors claimed via their Telegram channel that they completely compromised a Snowflake instance, ASOS has not publicly confirmed those specific claims, nor has it disclosed the exact identity of the compromised third-party platform.

Security researchers have noted the historical context surrounding data analysis platforms. For instance, campaigns by groups like ShinyHunters have previously targeted Snowflake instances across numerous organizations, though security experts emphasize that initial access vectors for the ASOS incident remain under investigation and unconfirmed.

Extortion Tactics and Industry Reaction

Industry experts highlighted that directly messaging customers through a mobile app is an unusual and deliberate move designed to extract maximum publicity. Security analysts note that leveraging media attention and public awareness is a classic extortion tactic employed by threat groups to pressure victim organizations into negotiations.

As investigations continue, security professionals continue to monitor whether the Xuanye Group's claims hold any merit or represent a broader threat to platforms utilized by enterprise environments.

Sources

Continue chronologically

You are readingASOS Confirms Cyberattack After Rogue In-App Notifications
Atlassian Patches Critical Vulnerability Affecting 8 Products
Older storyAtlassian Patches Critical Vulnerability Affecting 8 ProductsOctober 7, 2026 · 3 min