www.securityweek.com 7 Oct 2026, 09:46 UTC

ASOS Customers Hit by Rogue App Alerts After Cyberattack

ASOS Customers Hit by Rogue App Alerts After Cyberattack
CyberSIXT Evidence Panel Source marked as original reporting

ASOS has confirmed that a cyberattack affected its customer communications, with rogue notifications sent via a third‑party platform used to reach users. Over the past few days, many UK customers reported receiving a pop‑up within the ASOS app titled “ASOS hacked,” bearing a message allegedly from the attackers about compromising a Snowflake instance. ASOS said it immediately restricted access to the notification platforms and is working with internal and external advisers and authorities.

The retailer states that the attackers may have accessed basic customer information such as names and contact details, but ASOS emphasises that payment‑card data and account passwords were not impacted, and neither its website nor its app were disrupted. The company has not disclosed which third‑party platform was breached or who is behind the incident, and it does not claim that its Snowflake data platform itself was hacked.

Analysts cautioned that the threat actor group Xuanye Group claimed responsibility via a Telegram channel, though the attribution and the initial access method remain unconfirmed. Industry experts suggest the attack could represent extortionist signalling and highlight the potential implications for other organisations using Snowflake, pending a formal investigation.

View full article

Article by CyberSIXT