Hackers Turned ASOS’s Own App Into an Extortion Note

On October 6, 2026, millions of ASOS customers woke up to one of the most audacious cybersecurity moves in recent memory. Instead of the usual marketing offers and shipping updates, their phones displayed a chilling push notification: “ASOS HACKED — Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

The message, sent through ASOS’s own official mobile app, turned a trusted customer communication channel into a public extortion note — and it marks a disturbing escalation in how threat actors pressure their victims.

What Happened

At approximately 10:00 a.m. BST on October 6, customers across ASOS’s global user base received unauthorized push notifications through the retailer’s mobile app. The messages linked to a Telegram channel operated by a previously unknown group calling itself the “Xuanye Group.” The channel directed users to a second broadcast channel where the group posted its claims and demands.

ASOS moved quickly, posting an in-app notice urging customers to disregard the alert and avoid clicking the embedded Telegram link. In a statement to investors later that day, the London-listed company confirmed it was “investigating unauthorised activity involving third-party platforms” used to communicate with customers. It restricted access to those notification platforms and brought in external cybersecurity specialists. The UK’s National Cyber Security Centre (NCSC) is assisting in the investigation.

ASOS has not disclosed exactly which third-party notification service was compromised, nor how the attackers gained access to it. Security researchers have speculated that stolen credentials or compromised API keys for the push-notification platform may have been the entry point, but ASOS has not confirmed this.

The Snowflake Connection

The attackers’ central claim — that they “fully compromised” ASOS’s Snowflake instance — is what elevates this incident from a brand-embarrassing notification hijack to a potentially serious data breach. ASOS uses Simon AI for its marketing operations, which runs on the Snowflake cloud data platform. If the claim is true, the exposed data could include detailed customer profiles encompassing browsing behavior, purchasing history, location data, and loyalty program status, according to Pieter Arntz, a researcher at Malwarebytes.

Snowflake itself has pushed back. In a statement to the BBC, the company said its investigation is ongoing but that it has found “no compromise” of the Snowflake platform. However, security experts note that this language carefully distinguishes between a breach of Snowflake’s own infrastructure and unauthorized access to a customer’s individual Snowflake environment — a critical difference.

The distinction matters because the precedent is well established. In 2024, a wave of attacks on Snowflake customers hit at least 165 organizations, including AT&T, Ticketmaster, and Santander. Those breaches were traced not to a Snowflake platform flaw but to stolen credentials for individual customer accounts that lacked multi-factor authentication. If the Xuanye Group obtained valid credentials for ASOS’s Snowflake environment — whether through phishing, credential stuffing, or an infostealer — Snowflake’s platform could be perfectly secure while ASOS’s data was not.

Scope and Impact

ASOS has acknowledged that “basic personal information, including names and contact details, may have been accessed.” The company says it does not believe payment-card information or account passwords were affected. The Xuanye Group’s own Telegram posts, interestingly, echoed this, claiming payment data was not compromised and that the app remained safe to use.

The potential scale is significant. ASOS reports 16.5 million active customers across more than 100 markets, and its Android app alone has been downloaded over 10 million times on Google Play. While not every app user may have received the notification — some would have had push notifications disabled — social media reports and Reddit threads suggest the message reached a vast number of customers.

Financial markets reacted swiftly. ASOS shares plunged more than 14% during trading on October 6 before partially recovering to close roughly 10% down. The company has said it holds cyber insurance, including business-continuity coverage, but could not yet estimate the trading impact of the incident.

This is also not ASOS’s first security incident of the year. In July 2026, the company disclosed a credential-stuffing attack that exposed personal data — including names, addresses, phone numbers, and partial payment card details — of approximately 138,828 customers. That earlier incident, while smaller in scale, raises questions about the maturity of ASOS’s overall security posture.

A New Extortion Playbook

What makes the ASOS incident stand out is not the breach itself but the tactic. By weaponizing the retailer’s own notification infrastructure, the Xuanye Group bypassed every layer of corporate crisis communication. There was no opportunity for ASOS to control the narrative, issue a carefully worded disclosure, or manage the news cycle. Customers heard about the hack directly from the hackers.

Marie Wilcox of digital forensics firm Binalyze described the move as “psychological warfare,” designed to maximize pressure on ASOS by turning its customer base into an audience for the extortion demand. Jonathan Lee of TrendAI noted that the ability to send a push notification implies access beyond just a data warehouse — suggesting the compromise may extend further than the Snowflake environment alone.

Alan Snyder, CEO of mobile security firm NowSecure, put it starkly: “The mobile app is now a primary channel for customers. If compromised, it gives attackers access to customers on the front end and data on the back end. The same access that delivered an extortion threat could make a fake payment request look like routine customer service.”

The incident also fits into a broader pattern of attacks targeting UK retailers. In 2025, Marks & Spencer, the Co-operative Group, and Harrods all suffered significant cyberattacks, signaling that the retail sector remains a high-value target for cybercriminals.

What to Watch Next

Several questions remain unanswered. ASOS has not confirmed or denied whether its Snowflake environment was actually breached, what specific third-party notification platform was compromised, or how the attackers obtained access. The Xuanye Group, for its part, has not published any sample data to substantiate its claims — a departure from the typical playbook of more established extortion groups.

For ASOS customers, the immediate advice is straightforward: ignore the Telegram link, treat any unexpected emails or texts about your ASOS account with suspicion (since names and contact details can power convincing phishing campaigns), and get updates only from the official ASOS website or app. If you reuse your ASOS password elsewhere, change it now.

For the security community and the wider retail industry, the takeaway is more sobering. Every third-party integration — from cloud data platforms to push-notification services — is a potential attack surface, and every customer-facing channel is a potential megaphone for attackers. As Tom Exelby, a security consultant, advised: organizations should immediately audit who holds access to send app messages, what else that access enables, and how quickly it can be revoked. If ASOS’s experience proves anything, it is that the next breach notification might not come from the company at all.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.