ASOS Investigates Unauthorized Push Notifications After Attackers Claim Access to Customer Data in Snowflake

Views: 51 views

557/69 Friday, October 9, 2026

ASOS disclosed that it is investigating an unauthorized access incident after attackers used the company’s official mobile application to send push notifications directly to customers on October 6, 2026. The notification, titled “ASOS HACKED,” claimed that the attackers had compromised a Snowflake instance and threatened to publish the data unless ASOS made contact. The message also included a link to a Telegram channel operated by a group calling itself Xuanye Group, which has not previously established a clear presence in major cybercrime forums or leak sites.

ASOS confirmed that unauthorized push notifications were sent and advised customers to ignore the messages. The company restricted access to the affected notification platform and began working with cybersecurity specialists and relevant authorities. ASOS stated that the incident involved a third-party platform used for customer communications and that some basic information, such as names and contact details, may have been accessed. However, the company said it does not currently believe that payment card information or customer account passwords were affected. ASOS’s website and mobile application remain operational, with no reported impact on customer orders or core business operations.

Xuanye Group claimed on Telegram that it gained access to ASOS customer data stored in a Snowflake instance and stated that payment information was not affected and that the ASOS app remained safe to use. However, these claims have not been independently verified, and the group has not published samples of the data it claims to have stolen. Snowflake stated that it has begun investigating the incident and has found no evidence that the broader Snowflake platform was compromised. Incidents of this type may involve access to an individual customer account through stolen credentials rather than a compromise of the provider’s core infrastructure. ASOS users should rely only on information from the company’s official website or application, avoid clicking links received through Telegram, email, SMS, or social media, and remain alert for phishing messages that may reference ASOS accounts or orders using potentially exposed names and contact information.

Source: https://hackread.com/asos-hackers-hijack-app-notifications-snowflake-data-breach/