www.malwarebytes.com 6 Oct 2026, 14:11 UTC

ASOS investigates after hackers send breach threat through its app notifications

ASOS investigates after hackers send breach threat through its app notifications
CyberSIXT Evidence Panel Source marked as original reporting

THOUSANDS of ASOS customers reported receiving a push notification via the ASOS app alleging that the retailer has been hacked. The message, addressed to ASOS’s data protection officer and IT, stated: “ASOS HACKED … we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The notification appears to have travelled through ASOS’s own app infrastructure, which raises concern about unauthorized use of the notification system. The article notes that this does not confirm a Snowflake breach or data exfiltration, but the claim has not been independently verified.

ASOS’s marketing stack involves Simon AI running on Snowflake to personalise customer communications, alongside Braze for message delivery. If attacker access reached these systems, a breach could expose detailed customer profiles including browsing and purchase history, demographics, segments (such as Premier status or inactive customers), geolocation, and local weather data.

The Guardian reports the group behind the claim calls itself the “Xuanye group”; a Telegram channel message claimed that “payment information is not affected,” though this could not be independently verified. Sky News quoted a customer-service representative describing the push notification as “fraudulent” and said ASOS was investigating. At present, there is no verified evidence that customer databases, payment card details, or passwords have been stolen.

The article suggests the potential for targeted phishing using exposed data and advises caution, including postponing purchases until the situation is clarified and removing the ASOS app if access needs to be revoked.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline