ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker
British online fashion retailer ASOS is investigating unauthorised activity after attackers used its official mobile app to send threatening notifications directly to customers.
The notification, titled “ASOS HACKED,” appeared on customers’ phones on October 6, 2026. Screenshots shared by multiple recipients showed the same message:
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
The notification included a link to a Telegram channel operated by a previously unknown hacking group calling itself Xuanye Group.
The Telegram link included in the unauthorised ASOS notification did not open the group’s main channel directly. It first led to a gateway channel, which instructed visitors to follow a second link to what Xuanye Group described as its legitimate broadcast channel.
Hackread.com reviewed both channels. In the broadcast channel, the operators warned about impersonation and said the gateway would publish a replacement link if the main channel was removed.
The group then posted that ASOS customers’ payment information was not affected. In a later “final statement,” it claimed the ASOS app was safe to use and said the incident involved customer information held on its server.
“The incident involves customer information; it is safe on our server, and it will not be touched for a designated period,” the message stated.
The Telegram posts support the group’s claim that customer data was taken, but they do not prove the type, volume or authenticity of the information. Xuanye Group has not published a sample of the alleged data, and ASOS has only said that names and contact details may have been accessed.

ASOS later acknowledged that an unauthorised push notification had been sent and asked customers to disregard it. The company restricted access to the affected notification platforms and began working with cybersecurity specialists and relevant authorities.
Customer Names and Contact Details May Have Been Accessed
In a statement reported by Reuters, ASOS said it was investigating unauthorised activity involving third-party platforms used to communicate with customers.
“Basic personal information including name and contact details may have been accessed,” the company said. “We do not believe that payment-card information or account passwords were impacted.”
ASOS has not disclosed how many customers received the notification or how many records may have been accessed. It also has not named the third-party communication platforms involved.
The retailer’s website and app continued operating normally, with no disruption reported to orders or other business operations.
Access to the push-notification system confirms that the attackers reached at least one service connected to ASOS customer communications. However, ASOS has not explained whether that access came through compromised credentials, a third-party account or another security failure.
Xuanye Group Claims Snowflake Access
Xuanye Group claimed in its Telegram channel that it had accessed ASOS customer information stored in a Snowflake instance. The group also said payment information was not affected and that the ASOS app remained safe to use.
“The incident involves customer information, it is safe on our server, and it will not be touched for a designated period,” the group claimed.
Those statements have not been independently verified. The group appears to be new, with no established history on major cybercrime forums or leak sites before the ASOS incident.
Snowflake launched its own investigation after learning about the notification. A company spokesperson said it had found no evidence that the Snowflake platform itself had been compromised.
That statement does not settle whether attackers accessed an individual customer environment hosted on Snowflake. Previous incidents involving Snowflake customers resulted from attackers obtaining credentials for individual accounts, not from a breach of Snowflake’s central infrastructure.
In 2024, attackers accessed data belonging to at least 165 Snowflake customers, including AT&T, Ticketmaster and Santander. Investigators linked those incidents to stolen credentials and accounts that lacked multifactor authentication. Hackread.com previously reported on the arrest of a suspected hacker connected to those attacks.
No evidence currently connects Xuanye Group with the hackers involved in the 2024 campaign.
NCSC Assisting ASOS
The UK’s National Cyber Security Centre is providing assistance to ASOS. NCSC chief executive Richard Horne said the unauthorised notification showed how cyber incidents affecting large companies can also affect individuals.
ASOS shares fell by about 10% after the incident became public, having dropped by more than 14% during trading. The company said it holds cyber insurance, including business-continuity coverage, but could not yet calculate any effect on trading.
Customers should ignore the Telegram link included in the notification and treat unexpected emails, text messages or calls referring to ASOS accounts and orders with caution. Names and contact details can help criminals produce convincing phishing messages even when passwords and payment information have not been accessed.
ASOS customers should obtain updates through the retailer’s official website or app and avoid entering credentials through links received by email, text message or social media.


