ASOS confirms customer contact theft after rogue app alerts
ASOS says attackers stole customer names and contacts and sent rogue app alerts; a claimed Snowflake breach remains unverified.
On 6 October 2026, around 5:00 a.m. ET, ASOS app users received an unauthorized push titled "ASOS HACKED," addressed to the retailer's data protection officer and IT team and signed "xuanyewengateway." The previously unknown Xuanye Group claimed a full compromise of an ASOS Snowflake instance and a leak unless ASOS engaged on a Telegram channel created that day; sources disagree on reach, from dozens of users in BBC-cited coverage to thousands according to Malwarebytes. ASOS confirmed unauthorized access to third-party customer-communication platforms, restricted that access, and later told the London Stock Exchange that names and contact information were stolen; BBC reporting adds home addresses, phone numbers, email addresses, and profile notes such as website search queries, while ASOS does not believe payment cards or passwords were affected and has not said how many records were taken. Snowflake says its investigation found no platform compromise, so the Snowflake claim remains unverified, although ASOS marketing uses Simon AI on Snowflake with Braze and Horizon3 said notification access is separate and would imply credentials reached more than one system if both claims held. Reports say the intruders obtained logins by impersonating a trusted contact; Group-IB tied the Telegram account to earlier gaming-item trading, has seen no supporting data sample, and the channel had posted only three times, while Xuanye later claimed a theft without evidence and said payments were unaffected. The UK NCSC advises every ASOS customer to assume they are affected and avoid suspicious links; cited totals differ between 16.5 million active customers, with more than 10 million Android downloads, and about 17 million globally, shares fell more than 11% with an intraday drop of up to 13%, and a separate July credential-stuffing case has no confirmed link.
- On 6 October 2026, around 5:00 a.m. ET, an unauthorized "ASOS HACKED" app push signed "xuanyewengateway" reached users; sources put the audience at dozens (BBC) or thousands (Malwarebytes).
- Previously unknown Xuanye Group claimed a full compromise of an ASOS Snowflake instance and threatened a leak unless ASOS engaged on a Telegram channel created that day.
- ASOS confirmed unauthorized access to third-party customer-communication platforms, restricted that access, notified authorities, and later told the London Stock Exchange that customer names and contact information were stolen.
- BBC reporting adds home addresses, phone numbers, email addresses, and profile notes such as website search queries; the number of records taken is undisclosed.
- ASOS does not believe payment-card data or passwords were affected, and its website and app remained up.
- Snowflake says its investigation found no compromise of its platform, so the Snowflake claim is unverified; ASOS marketing uses Simon AI on Snowflake with Braze.
- The UK NCSC advises every ASOS customer to assume they are affected, avoid suspicious links, and watch for phishing; cited totals differ between 16.5 million active customers and about 17 million globally.
- Shares fell more than 11%, with an intraday drop of up to 13%; Group-IB found no supporting data sample and tied the Telegram account to earlier gaming-item trading.
Coverage timelineoldest first · each row is one article
- · 2d agoShares in British clothing company ASOS dive after hackers apparently send push notification
The Record· 60
ASOS shares fell over 10% after an unconfirmed app alert claimed hackers compromised its Snowflake data environment.
- · 2d agoASOS app users receive push notifications apparently sent by hackers
Hacker News · security· 70
ASOS app users got hacker alerts from new Xuanye Group claiming a Snowflake compromise.
- · 2d agoASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
Infosecurity Magazine· 68