A UK-based online fashion retailer, ASOS, has confirmed a data breach after hackers sent unauthorized push notifications through its mobile app, claiming to have stolen customer data from the company’s Snowflake environment. The breach is the latest in a string of high-profile attacks on major brands, highlighting the ongoing threat posed by sophisticated cybercriminals.
ASOS, which sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States, has confirmed that third-party platforms used to communicate with customers were accessed without authorization. The company says basic personal information, including names and contact details, may have been exposed in the breach. However, ASOS claims that payment-card information or account passwords were not impacted.
The hack began on Tuesday morning, when multiple ASOS customers reported receiving a notification on their mobile app, which read “ASOS HACKED” and directed them to a Telegram channel operated by a threat actor calling itself the “Xuanye group.” The attackers claimed to have compromised ASOS’s Snowflake environment, but provided no evidence to support this claim. In messages posted to the Telegram channel, the Xuanye group claimed that customer information was safe on their server and would not be touched for a designated period.
The breach highlights the growing threat posed by sophisticated cybercriminals who are increasingly targeting major brands. The attackers in this case appear to have exploited vulnerabilities in ASOS’s mobile app and third-party platforms to gain access to customer data. While ASOS has confirmed that payment information was not impacted, the company still needs to provide more information about the scope of the breach and how it occurred.
The incident also raises questions about the effectiveness of cybersecurity measures at major brands. While ASOS claims to have robust security protocols in place, the attackers were able to exploit vulnerabilities in its systems and compromise customer data. This highlights the need for companies to stay vigilant and continually update their security measures to keep pace with evolving threats.
In practical terms, customers who received the unauthorized push notification should disregard it and not click or engage with any external links. ASOS is now displaying an in-app notice advising customers of the breach and urging them to be cautious when using its mobile app.
Ultimately, the ASOS breach serves as a reminder that no company is immune to cyber threats, and even major brands can fall victim to sophisticated attacks. As a result, consumers need to remain vigilant and take steps to protect themselves online, such as using strong passwords, enabling two-factor authentication, and regularly monitoring their accounts for suspicious activity.
Source: Bleeping Computer — 2026-10-06