ASOS Got Hacked Through Its Own Customer Notification Channel, and the Attackers Used It to Taunt Shoppers Directly
Cybersecurity

ASOS Got Hacked Through Its Own Customer Notification Channel, and the Attackers Used It to Taunt Shoppers Directly

Attackers compromised a third-party platform ASOS uses to message customers and sent UK shoppers rogue app notifications claiming to have breached a Snowflake instance. ASOS confirmed the breach but has not named the platform or confirmed the Snowflake claim.

PublishedOctober 8, 2026
Read time5 min read
Share

What happened to ASOS customers

Over the days before October 7, UK users of the ASOS mobile app began receiving rogue pop-up notifications titled ASOS hacked, pushed through the app's own notification system rather than email or a leak site. One notification claimed the attackers had fully compromised the Snowflake instance and threatened a data leak unless the company engaged with them. ASOS filed a statement with the London Stock Exchange, reportedly on October 6, confirming that attackers had compromised a third-party platform the retailer uses for customer messaging and used it to send the unauthorized notifications.

ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external advisers and relevant authorities. The company stated its website and app were not themselves affected and that operations continued without disruption. Critically, ASOS has not named the compromised platform, and the Snowflake reference comes only from the attacker's own notification text, not from ASOS's confirmation. Whether Snowflake specifically was involved remains unverified as of this writing.

What data is actually at risk

According to ASOS, the attackers may have accessed basic user information, limited to names and contact details. The company says it does not believe payment card information or account passwords were affected, and no total figure for affected users has been disclosed. That is a meaningfully narrower exposure than a full Snowflake instance compromise would suggest, and the gap between the attacker's claim and ASOS's confirmed scope is itself useful information: either the attacker is overstating access for leverage, or ASOS's visibility into the compromised platform is still incomplete days after the notifications began. A retailer in that position faces a genuine communications dilemma, since confirming too little looks evasive and confirming too much before the investigation is complete risks correcting the record later in a way that reads as a second disclosure failure.

A threat actor using the name Xuanye Group claimed the attack through a newly created Telegram channel. Forescout Research's Daniel dos Santos noted the name suggests a Chinese-speaking actor but cautioned it could be a false flag, a reminder that attribution claims made for leverage during active extortion should be treated as unverified regardless of what name or nationality they imply. A freshly created channel with no prior posting history is itself a weak signal either way, since both genuine new crews and established actors running a deliberate false flag would present identically to an outside observer at this early stage.

Why the Snowflake claim matters even unconfirmed

Dos Santos drew a direct parallel to 2024, when the ShinyHunters campaign breached Snowflake instances belonging to more than 160 organizations using credentials harvested through infostealers rather than any flaw in Snowflake itself. He said this recent hack may be similar, although it is not confirmed what the initial access was. That caveat is important: a Snowflake-adjacent breach caused by stolen customer credentials is a very different problem than a vulnerability in Snowflake's platform, and conflating the two leads to the wrong remediation.

Natalie Page of Talion Cyber Security went further, arguing that if Snowflake was in fact exploited here, it should be investigated as a priority precisely because other organizations using the same platform could be affected by whatever access method worked against ASOS. For any retailer or SaaS company using Snowflake or a comparable data platform for customer communications infrastructure, an unconfirmed claim naming that platform in an active extortion attempt is still a reasonable trigger to review your own credential hygiene on that platform now, rather than waiting for ASOS or Snowflake to confirm the mechanism.

The extortion tactic itself is the escalation

Page also flagged something easy to miss amid the data-exposure questions: messaging customers directly through the company's own app is a deliberate extortion tactic meant to generate publicity and pressure the victim organization faster than a typical dark-web leak-site posting would. A leak site threat gives a company days or weeks of quiet negotiation room before public exposure. A notification pushed into tens of thousands of customers' phones overnight removes that room entirely and forces a public response on the attacker's timeline, not the victim's.

For a retail or consumer-facing business, this is a distinct incident response scenario that deserves its own plan, separate from the standard breach-notification playbook built around regulatory deadlines. A customer-facing extortion push requires an immediate public statement capability, pre-drafted holding language for exactly this situation, and a decision tree for how quickly legal, communications, and security leadership can align on a public response measured in hours, not the days a typical disclosure timeline assumes.

What this means for third-party communication vendors

ASOS's core infrastructure, by its own account, was not touched. The breach reached customers entirely through a third-party vendor's platform that ASOS trusted with direct push access to its own app's notification channel. That is a vendor risk category that often gets less scrutiny than a payment processor or a core data warehouse, precisely because a notification platform does not typically hold the most sensitive data. This incident shows that access, not data sensitivity alone, defines the blast radius: a vendor with the ability to push content directly to your customers can damage your brand and your customers' trust even if it never touches a credit card number.

Retail and commerce technology leaders should inventory every third-party platform with direct customer-facing push or messaging access, not just data-handling vendors, and ask a specific question about each one: if this vendor were compromised tomorrow, could the attacker message our customers directly, and what would we need in place to respond within hours rather than days. ASOS's answer to that question is playing out publicly right now, and it is a cheaper lesson to learn from their incident than from your own.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#third-party-risk#retail#extortion#data-breach#asos#snowflake#shinyhunters#customer-communications