ASOS confirms data breach: third-party customer messaging platforms accessed, names and contact details may be exposed after an extortion push notification claimed its Snowflake instance was "fully compromised"; Snowflake claim unconfirmed
On 6 October 2026, from about 5am US Eastern time, users of the ASOS shopping app, mainly in the UK, received a push notification addressed to the British online fashion retailer's data protection officer and IT team: "we have fully compromised the Snowflake instance. Engage with us, or we will leak it", with a link to a Telegram channel run by a group calling itself Xuanye, which has no known track record. Later the same day ASOS confirmed a data breach: it says third-party platforms it uses to communicate with customers were accessed without authorisation and that basic personal information, including names and contact details, may have been exposed. ASOS says it does not believe payment card details or account passwords were affected, and it is showing an in-app notice telling customers to ignore the alert and not to open its link. ASOS has not confirmed the claim that its Snowflake environment was compromised and has not said how many customers are affected. The group first said payment data was not affected, then posted a "final statement" claiming it holds customer information and will not touch it "for a designated period"; it has published no evidence or numbers. Researchers quoted by the BBC said sending the notification needed access to ASOS's own messaging systems. ASOS shares fell more than 11% on 6 October (Reuters). Sources: BleepingComputer (ASOS confirmation), BBC News, The Register.
- Product
- ASOS third-party customer communication platforms (push notifications); claimed access to a Snowflake data instance (unconfirmed)
- Versions
- n/a — incident; no CVE or product flaw identified
- Exploited in Australia?
- unknown
- Patch to
- ASOS customers: ignore the notification and the Telegram link, expect phishing by email, SMS or phone that uses your name and contact details and mentions ASOS, and change your ASOS password if you reuse it elsewhere. Organisations: treat push-notification and customer-messaging consoles and their API keys (Firebase, APNs, OneSignal, Braze and similar) as high-privilege systems with MFA, least-privilege access and alerts on unusual sends, and review Snowflake and other data-platform logins for credential misuse, enforcing MFA and network policies on every account.
Primary: BleepingComputer — ASOS confirms data breach after "HACKED" in-app notifications (6 Oct 2026) · BBC News — 'ASOS hacked': app users receive notifications apparently sent by hackers (6 Oct 2026)
