Hackers push 'ASOS hacked' alert to shoppers through the retailer's own app

06.10.2026 3 min 51

ASOS shoppers in several countries got an unusual push notification from the retailer's own app on Tuesday morning, October 6: "ASOS hacked". The message was not meant for customers. It was a ransom demand addressed to the company: "Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it", followed by a link to a Telegram account. ASOS says it is investigating and has not confirmed that any data was stolen.

What happened

The alert went out at around 10am UK time and was reported by users in the UK, the US, Germany and Australia. Snowflake is a cloud data platform that many large companies use to store and analyse customer data; the attackers claim they have full access to ASOS's account there. City AM reports that the group calls itself "Xuanye Group" and claims payment details were not affected. None of this has been verified, and it is not known whether ASOS stores customer data in Snowflake at all.

ASOS said: "We're aware of the notification and are currently investigating. We don't have any further information to share at this stage, but we'll provide an update as soon as we know more." Its shares fell by about 10% on the London Stock Exchange that morning.

Sending a ransom note through a company's own customer channel is rare. Extortion gangs usually negotiate in private, and here, according to ITV, the threat reached thousands of customers' phones at once, together with the share price drop. The fact that the attackers could send a push notification at all means they had access at least to the app's notification system, whatever the truth about the database.

Why Snowflake keeps coming up

Snowflake was at the centre of a wave of breaches in 2024, when attackers logged in to the Snowflake accounts of companies including AT&T, Ticketmaster and Santander. Mandiant counted about 165 organisations that were potentially exposed. The passwords had been stolen earlier by infostealer malware, and the accounts had no two-factor authentication. According to Mandiant, Snowflake's own systems were not breached; every case traced back to stolen customer credentials. Whether something similar happened at ASOS is unknown.

What ASOS customers should do

  • Ignore the Telegram link in the notification. It leads to the attackers, not to ASOS.
  • Expect phishing. After an incident like this, fake emails and texts "from ASOS" about refunds, account checks or vouchers usually follow. Do not click links in them; open the app or type the address yourself.
  • Change your ASOS password if you use the same one anywhere else, and change it there too.
  • Watch your card statements. The attackers claim payment data is safe, but that claim is worth nothing on its own.

If ASOS confirms a breach, under UK data protection law it must tell affected customers if the leak puts them at high risk.

asossnowflakeunited kingdomdata breachextortionphishinghackerscybersecurity

Read also