ASOS customers were left alarmed this morning after the retailer’s own mobile app delivered a push notification claiming the company had been hacked and threatening to leak data unless it opened negotiations with the attackers.
The notification, titled “ASOS HACKED” and sent out at around 10am BST on Tuesday, was addressed not to shoppers but to the company itself. It read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The message included a link to a Telegram channel, and users in several countries reported receiving it.
ASOS has not yet issued a public statement or confirmed whether its Snowflake environment has been accessed. Downdetector recorded roughly 500 reports of problems from around 9.40am, the vast majority relating to the app rather than the website, and the company’s share price dropped by around 5% in the 30 minutes after the notification landed.
Dray Agha, senior manager of security operations at Huntress, said: “Snowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the ASOS mobile app also. This is clear public extortion. Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation.”
His colleague Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the method of delivery was arguably as damaging as any theft: “The attackers didn’t just steal from ASOS. They used ASOS’s own voice to tell its customers about it. That’s not just a data breach. That’s a complete loss of operational control, and the reputational damage from that alone is significant.”
Markets react before the facts are known
Charlotte Wilson, head of enterprise for the UK & Ireland at Check Point, said: “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note. The fact ASOS shares fell by almost 5% within minutes of the reports emerging is a reminder that cyber security is now inseparable from commercial performance and corporate reputation. Before the company had even publicly established what had happened, investors were already pricing in the potential consequences.”
She added: “Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company. The fact that an attacker may have been able to hijack that relationship and send a threat directly to customers demonstrates how quickly a cyber incident can move from the server room to the front page, and then straight into the market value of a business. The reference to Snowflake will understandably raise questions about customer data, but we should be careful not to speculate about what has actually been accessed until ASOS has established the facts. Right now, the priority will be containing the intrusion, understanding exactly which systems and data have been compromised and closing off any continuing access.”
Echoes of the 2024 Snowflake campaign
The mention of Snowflake will inevitably recall the 2024 wave of attacks on the cloud data platform’s customers, in which stolen credentials were used to raid corporate accounts and the data was then used to extort victims.
Daniel dos Santos, VP of research at Forescout, said: “Snowflake is a data analysis and AI platform used by several organizations. In 2024, ShinyHunters hacked Snowflake instances of over 160 organizations and stole sensitive data that was used for extortion. They used credentials obtained from infostealers for initial access. This recent hack may be similar, although it is not confirmed what the initial access was.”
He continued: “Snowflake has published more than 20 vulnerabilities on their products in 2026, including three considered high criticality in September, but none of those is known to be exploited by threat actors.”
ASOS has dealt with account security problems recently. In August, its US business notified customers that their accounts had been accessed using login credentials obtained from outside the company, after detecting unusual activity in late July. There is no indication at this stage that the two incidents are connected.
An unknown group seeking attention
The Telegram link in the notification points to a channel calling itself Xuanye Gateway, which appears to have been set up only hours before the message went out.
“The threat actors provided a link to a Telegram channel created today that already has 150+ subscribers. That channel then links to a group chat with more than 260 participants,” said dos Santos. “‘Xuanye’ is not a known threat actor, but the name is of Chinese origin, which could indicate a Chinese-speaking threat actor or simply a false flag.”
Michele Campobasso, senior security researcher at Forescout, warned that ASOS may not be the group’s last target: “The lack of any additional information and the (short) presentation of a group suggests that the threat actor is planning to claim more attacks. It may be worth monitoring; despite the potential low technological complexity of this attack, it is something visible to a large population and will result in media attention. By exploiting the obtained attention, threat actors may follow up with more, potentially similar attacks.”
Jamie Akhtar, CEO and Co-founder of CyberSmart, said the full scale of the incident would depend on how far the attackers had got: “One possibility is that attackers gained access to a system used to send customer notifications and broadcast an extortion demand to put pressure on ASOS. However, if hackers have managed to gain access to more of the ASOS systems than just their app notifications then the impact could be severe for ASOS themselves, customers and third-party businesses.”
“If attackers sent this notification through ASOS’s app, it would be an unusual and highly public way of applying pressure to the business, bringing an extortion threat directly to customers through a channel they would normally trust,” he added.
Phishing warning for shoppers
Security experts are urging customers not to click the link in the notification and to watch for follow-up scams. Akhtar said: “For customers, the immediate impact is uncertainty and concern, alongside reported website issues. If personal information has been accessed, it could enable more convincing phishing attempts and fraud. Customers should avoid clicking the link in the notification and check ASOS’s official website directly for updates.”
Agha echoed that warning: “I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.”
Wilson said: “For customers, the biggest immediate risk may be what happens next. Criminals know people will be searching for information about the ASOS hack, and we would expect attempts to exploit that confusion. Customers should be extremely suspicious of emails, texts or messages claiming their ASOS account has been compromised, offering refunds or asking them to reset passwords through a link. Go directly to the ASOS app or website rather than following links sent to you.”
Javvad Malik, Lead CISO Advisor at KnowBe4, said: “Details are scarce at the moment, but one thing is abundantly clear, that a threatening messaging coming through a trusted trap can rattle anyone. The anxiety and uncertainty can lead people to make decisions which could impact them negatively going forward.”
He added that the onus is now on the retailer to take back control of the conversation: “ASOS needs to communicate clearly and properly through verified channels, explain what is known and unknown, and give people clear, practical steps. It’s imperative that people don’t engage with the criminals.”
A lesson for every business
Akhtar said the incident should prompt organisations to look hard at third-party access: “For businesses, compromised supplier accounts or credentials could expose information or disrupt services. Businesses need to understand who can access their data, limit that access, check suppliers’ security arrangements and agree how incidents will be handled. Outsourcing a service does not remove responsibility for protecting customers.”
Wilson concluded: “For every other business watching this unfold, there is a stark lesson. Cyber-attacks no longer stay inside IT departments. They can hit customers, reputation and shareholder value almost simultaneously. In this case, customers appear to have heard from the alleged attackers before they heard from the company itself. Organisations need to be prepared for attackers to seize the communications initiative, because once criminals can speak to your customers through your own systems, the commercial impact can begin almost immediately.”





