ASOS confirms data breach after “HACKED” in-app notifications

A UK-based online fashion retailer, ASOS, has confirmed a data breach after hackers sent unauthorized push notifications through its mobile app. The notification, which claimed to have been sent by the company’s Data Protection Officer and IT department, read “ASOS HACKED” and directed users to a Telegram channel operated by the threat actor.

The breach is believed to have affected ASOS customers worldwide, including in the United States. While the exact number of impacted customers remains unknown, it’s clear that many, if not all, mobile app users received the unauthorized notification on Tuesday morning. The company has confirmed that basic personal information, such as names and contact details, may have been exposed through third-party platforms used to communicate with customers.

The hackers, who claim to belong to a group called the “Xuanye group,” initially stated that they had compromised ASOS’s Snowflake environment, which is a cloud-based data warehousing platform. However, it appears that this claim has not been substantiated by any evidence. The attackers have published a statement claiming to have stolen customer information in the attack, but details on what specific information was taken and how many customers were impacted remain unclear.

ASOS has assured its users that payment-card information and account passwords were not affected by the breach. In response to the incident, the company is displaying an in-app notice advising users to disregard the unauthorized push alert and not engage with any external links it contains. While this may be a reassuring message for customers, it’s essential to note that the hackers have claimed to have taken sensitive information from ASOS’s Snowflake environment.

The unauthorized notifications were sent through third-party platforms used by ASOS to communicate with its users. This highlights a critical vulnerability in the company’s security measures and underscores the importance of robust communication protocols. ASOS has not confirmed how many customers are affected or what specific steps it will take to prevent similar incidents in the future.

As this incident unfolds, it serves as a reminder that even large companies like ASOS can fall victim to data breaches. It’s crucial for consumers to remain vigilant and proactive in protecting their personal information online. To mitigate potential risks, users should be cautious when receiving unsolicited notifications or messages from unknown sources, especially those claiming sensitive information has been compromised.

In conclusion, this incident highlights the ongoing cat-and-mouse game between threat actors and companies looking to protect their customers’ data. As cybersecurity threats continue to evolve, it’s essential for organizations to prioritize robust security measures and transparent communication with their users.


Source: Bleeping Computer — 2026-10-06