
Hackers Breached ASOS — Then Announced It Through the ASOS App Itself
Mahmud Hasan
October 9, 2026
The notification came from the real ASOS app. That was the problem.
Millions of phones buzzed with an alert titled "Asos hacked." It wasn't a phishing text or a scam email pretending to be the retailer — it was a genuine push notification, delivered through the official ASOS app. The message wasn't addressed to customers, either. It was addressed to ASOS's own data protection officer and IT department: the hackers, calling themselves the Xuanye Group, claimed to have fully compromised the company's Snowflake data instance and ended with an ultimatum — "Engage with us, or we will leak it," plus a Telegram contact link.
The attackers hadn't just broken in. They'd stolen the megaphone.
What happened, in order
The timeline is short and ugly. On October 6, 2026, ASOS customers around the world received the rogue notification through the company's app. In a filing with the London Stock Exchange that day, ASOS confirmed that hackers had broken into a third-party platform it uses to communicate with customers.
By Thursday, October 8, after roughly 48 hours of investigation with external security experts, law enforcement, and regulators, ASOS emailed customers with a fuller account. An "unauthorised party," the company said, had gained access to an ASOS employee's account "by impersonating a trusted contact to obtain log in credentials." Those credentials were then used to get into third-party platforms ASOS relies on.
Read that again, because it's the whole story in two sentences. No zero-day. No malware. One employee was tricked by someone pretending to be a person they trusted, and that one login opened doors into the company's customer-communications stack — the systems that can push a message to millions of phones at once.
What was taken — and what the hackers say they want
ASOS says the stolen data includes names and contact details. The BBC, whose cybersecurity reporter Joe Tidy actually spoke with the threat actor, reported a more detailed haul: home addresses, phone numbers, email addresses, and profile notes like customers' website search queries. The actor sent Tidy a sample of the data — reportedly more detailed than what ASOS had publicly acknowledged at that point — and the BBC held off publishing to give the company time to respond and contact customers.
Two things matter here. First, ASOS stresses that no payment card information or account passwords were accessed. But don't mistake "basic personal information" for harmless. A database of 17 million real names, addresses, phone numbers, and email addresses — ASOS cites the 17 million figure on its own site — is a phishing factory. The most likely follow-on to this breach isn't a second breach; it's a wave of convincingly personalized scam messages and calls, which is exactly why ASOS's customer email warns people to stay suspicious of anything claiming to be from the company. "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call," the email reads. That line is in every breach-notification email for a reason: it's usually what happens next.
The Snowflake question, and the Simon AI twist
The hackers' notification claimed a compromised "Snowflake instance." Snowflake, the cloud data platform, says its own systems weren't breached: "At this time, we can report that we have found no compromise of the Snowflake platform." The distinction matters: this was stolen credentials for an ASOS-run Snowflake instance — almost certainly on a third-party platform built on top of it — not a flaw in Snowflake's own infrastructure.
Malwarebytes researcher Pieter Arntz pointed to an agentic marketing platform called Simon AI — built on Snowflake Cortex AI — whose website advertises its partnership with ASOS. Simon AI was acquired by the software firm Monetate this past July. When the BBC's Joe Tidy spoke to the Xuanye Group, the actor claimed it was a Simon AI instance they compromised to reach the data. That claim is unconfirmed, but the shape of it is the important part: a marketing platform, built on an AI data service, sold to a retailer for customer engagement, becomes the path into customer data.
Count the links in that chain. Retailer → marketing platform → AI data service → credentials → 17 million customer records → the company's own push-notification system turned into a ransom note. Every third party you hand customer data to is a door, and every door you hand to a third party is a door you can't watch.
Why this breach is different from the usual "data was exposed" story
Most breaches announce themselves weeks later, in an email nobody reads, offering a year of credit monitoring. This one announced itself instantly — on the victims' lock screens, in the company's own voice channel. That's not just drama; it changes the threat model.
Push notifications carry the app's branding, arrive with system-level authority, and most people read them reflexively. When attackers can send through that channel, they get the company's credibility for free — and any customer trained to trust "a message from the ASOS app" becomes one social-engineering step easier to fool. The Betterment incident earlier this year is the proof this isn't a one-off: hackers got into a third-party marketing platform used by the fintech and impersonated the company to push a crypto scam to its customers, while also walking away with names, emails, and phone numbers.
There's a second difference worth naming. The classic playbook is "pay or we leak it," delivered quietly to the security team or dumped on a leak site. Here the ransom demand was pushed to the customers themselves, addressed to the company's own security staff, in public. It's pressure-by-audience: force the company's hand by making sure 17 million people are watching. Expect to see this move again, because it clearly works — ASOS shares fell as much as 14% on Tuesday when the alert went out.
What to do about it
If you build or run products with customer data: audit your third-party platforms the way you'd audit your own code. The push-notification service, the marketing platform, the analytics warehouse — each one is a production system holding real credentials. Ask three questions this week: which vendors can send to all our users at once, is access to those systems behind multi-factor authentication, and would we know if someone used them? ASOS hasn't said whether its Snowflake instance had MFA enabled; Bleeping Computer reports it's still unclear. That's a question no incident response should leave unanswered twice.
If you work in security awareness: this incident is a free training module. One tricked employee, one set of credentials — no exploit needed. Phishing simulations and "verify out of band" policies exist for exactly this scenario. They fail for the same reason they failed here: the attacker didn't look like an attacker.
If you're an ASOS customer: expect targeted phishing. The combination of your name, address, phone, email, and what you searched for on the site is enough to craft very convincing "ASOS delivery issue" texts and calls. ASOS says no action is needed on your account — but treat any message claiming to be from them, especially one creating urgency, as hostile until proven otherwise. Use the app or type the website address yourself instead of clicking links.
The uncomfortable lesson of the ASOS breach is that the weakest link wasn't a server — it was a conversation. One person trusted the wrong message, and millions of phones buzzed with the consequences.
References
- TechCrunch — Asos confirms breach of customer data after hackers send rogue app notification
- Reuters — UK's ASOS says breach exposed some customer personal data
- BleepingComputer — ASOS links data breach to social engineering attack, credential theft
- Infosecurity Magazine — ASOS Confirms Data Breach Linked to Stolen Employee Credentials
- The Times — Asos hacked when attacker impersonated trusted contact
Comments
More in Cybersecurity

Bangladesh Got Satellite-to-Mobile Before India. Your 4G Phone Didn't Change — the Sky Did.
Banglalink and Starlink launched South Asia's first direct-to-cell service on October 7: your existing 4G phone and SIM can now text and share location through satellites in dead zones. Here's how the orbital cell towers work — and what they can't do yet.
Read more
