ASOS has confirmed a data breach after attackers used the retailer’s mobile app to send an unauthorized push notification claiming a full compromise of its Snowflake instance. The alert reached app users in several countries on October 6 and told the company to negotiate or face a data leak.
How the Fake Push Notification Reached ASOS App Users
At about 5:00 a.m. ET, ASOS app users received a push notification that read: “ASOS HACKED. Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The message did not come from ASOS. It was sent by an outside party that had gained the ability to push alerts through the retailer’s app.
Users in the United Kingdom, the United States, Germany and Australia received the notification. Because push alerts appear directly on a phone’s lock screen, the message reached customers without any need for them to open the app or visit a website.
What the Xuanye Group Message Claimed About Snowflake
The notification was signed by a group calling itself “Xuanye Group.” It addressed ASOS’s data protection officer and IT staff by role, which framed the message as an extortion demand aimed at the company rather than a warning to shoppers. The text asserted that the attackers had fully compromised ASOS’s Snowflake instance and threatened to leak the contents if the company did not engage with them.
The notification also pointed recipients to a Telegram channel run by the attackers. That channel gave the group a public venue to continue its pressure campaign outside ASOS’s own systems.
What ASOS Has Confirmed and What It Has Not
ASOS confirmed that a breach took place. It has not confirmed the attackers’ claim that its Snowflake environment was compromised, and it has not said how many customers were affected. The company also has not described how the attackers obtained access to the push notification system.
That leaves a gap between what the attackers say they hold and what ASOS has verified. The Snowflake claim comes only from the group’s own message, and no independent confirmation of it has been reported.
ASOS Response and Customer Exposure
After the alert went out, ASOS displayed an in-app warning telling customers to ignore the notification and not to click any external links. The warning was aimed at preventing recipients from following the attackers’ pointer to the Telegram channel or to any other link connected to the message.
The company’s investigation is ongoing. No regulator action has been reported so far.
Names and Contact Details Potentially Exposed
ASOS said that customer names and contact details were potentially exposed in the incident. The company said payment card data and account passwords were not affected. Those two categories are the ones most often used for direct financial fraud and account takeover, and ASOS’s statement places them outside the confirmed scope of the breach.
Names and contact details can still be used to target customers with phishing messages that appear to come from the retailer. ASOS has not said how many people’s details may be involved, so the size of the exposed group remains unknown.
Why a Hijacked Notification Channel Matters for Retailers
The ASOS incident shows an extortion message delivered through a company’s own customer-facing channel. In this case the attackers did not rely on a ransom note sent privately to executives or a post on a leak site. They used the retailer’s app to reach customers in four countries at the same moment, putting the extortion demand in front of the public.
Retailers hold large volumes of customer names and contact details, and app notification systems give them direct access to those customers. The ASOS message turned that direct line into a public pressure tool, aimed at forcing a response from the company’s data protection and IT teams.
What Remains Unconfirmed
Several central questions are open. ASOS has not said whether Snowflake was accessed, how many customers are affected, or how the attackers got into its push notification capability. It has not said whether it will notify affected customers individually.
One secondary outlet reported a drop in ASOS’s share price after the incident. That figure has not been verified and is not included here.
The incident remains under investigation, and ASOS has said the potentially exposed data is limited to names and contact details. Whether the Xuanye Group follows through on its threat to leak data, and what material it publishes if it does, will determine how the company’s account of the breach holds up.