ASOS plc, the British online fashion and cosmetics retailer, confirmed on 6 October 2026 that hackers had broken into a third-party customer communication platform and then used the company's own mobile app to broadcast an unauthorised push notification to shoppers. The message, titled 'ASOS hacked', addressed the retailer's data protection officer and IT department and declared that the attackers had 'fully compromised' the company's data hosted on Snowflake, a cloud platform that lets corporate customers analyse very large volumes of information. It closed with a threat: 'Engage with us, or we will leak it.'
The notification reached users across the United Kingdom on the morning of Tuesday, 6 October 2026, and many of them posted screenshots to social media. ASOS moved quickly to restrict access to its notification platforms and, several hours later, confirmed to shareholders through a filing with the London Stock Exchange that a third-party platform used for customer communication had been compromised. The company said its website and app remained safe to use and that its operations had not been disrupted, but it also acknowledged that personal data including names and contact details may have been accessed in an attack that occurred at about 10 a.m. that day.
The immediate market reaction was severe. ASOS shares fell as much as 15 per cent in London, the steepest intraday decline since May 2023, before slightly paring the loss. What ASOS initially described as basic contact details turned out to include home addresses, phone numbers, email addresses and dates of birth, alongside records of what customers had searched for on the site.
The attackers called themselves Xuanye Group, also written Xuanyewen, and claimed responsibility on a newly created Telegram channel. Security researchers said the name points towards a Chinese-speaking threat actor, while cautioning that it could also be a false flag designed to send investigators in the wrong direction. The group has not indicated how much data it holds, and neither ASOS nor the third parties named in the notification have explained how the intrusion progressed from a single stolen login to a mass notification delivered through the retailer's own software.
Key Facts
ASOS has told customers that hackers are in possession of detailed profiles of potentially millions of the online store's users. Names, addresses, phone numbers, emails, customer numbers and dates of birth are now in the hands of criminals, according to the BBC, which was contacted by the attackers. The stolen records also include the searches customers made on the website, with terms such as 'reclaimed vintage', 'glamorous wide fit' and 'Asos petite' visible in the sample of data that the criminals shared. BBC News reported on October 8, 2026, that the breach went beyond the 'basic contact details' ASOS first disclosed.
ASOS said the attackers impersonated a trusted contact to obtain an employee's login credentials and then used that compromised account to access information held on certain third-party platforms. It said payment-card information and account passwords were not impacted, that customers did not need to take action on their accounts and that shoppers should remain cautious of unexpected messages or calls claiming to come from the company. 'We will never ask you to share passwords, security codes or payment details through an unsolicited message or call,' ASOS told customers. Retail Systems reported on October 9, 2026, that shares fell by more than 13 per cent after the incident became public on Tuesday, although they recovered following Thursday's update.
Snowflake, the cloud data platform named in the rogue notification, said it had not experienced a breach of its own systems. The criminals told the BBC they used a platform built natively on top of Snowflake, called Simon AI, to reach the data. TechCrunch reported on October 8, 2026, that the hackers broke into the Snowflake instance by impersonating a trusted contact to obtain login credentials. SecurityWeek reported on October 7, 2026, that ASOS confirmed the unauthorised notifications after a third-party platform used for customer communication was hacked, and that the retailer did not share which platform was compromised.
It is unclear whether the ASOS-run Snowflake instance was protected with multi-factor authentication, and it is not known how the hackers gained access to the in-app push notification system. ASOS said it locked down the affected platforms to prevent further unauthorised access, launched an investigation with internal and external cybersecurity experts, is working with law enforcement and regulatory authorities, and has introduced additional security controls. The company has roughly 16.5 million to 17 million customers, which gives the stolen profiles a very large pool of potential targets. Bloomberg Law reported on October 6, 2026, that the stock fell as much as 15 per cent in London that day, the most intraday since May 2023.
Analysis
The mechanics of this intrusion matter less than the choice of channel. Attackers did not need to buy advertising or register a lookalike domain to reach millions of ASOS shoppers; they simply used the company's own app, a surface that customers have been trained to trust. What this really means is that the boundary between an internal platform compromise and a full-scale brand crisis has effectively disappeared. A stolen employee credential, a third-party communication tool and a push notification were enough to make a data breach visible on the lock screens of a national customer base.
SecurityWeek quoted Daniel dos Santos of Forescout Research, who noted that in 2024 ShinyHunters hacked Snowflake instances of more than 160 organizations using credentials obtained from infostealers for initial access, and who said the recent hack may be similar. The Snowflake campaigns of 2024 showed that cloud data warehouses are only as strong as the identity controls around them, and that credentials captured by commodity malware can open doors at enormous scale. If the ASOS incident follows the same pattern, the critical failure may sit in authentication practice rather than in any single product.
ASOS has handled the disclosure in stages, confirming the platform compromise on 6 October and then widening the description of stolen data as evidence arrived. The pace and precision of those statements are likely to draw scrutiny, particularly given the range of personal information involved and the fact that dates of birth and search histories make phishing and impersonation attacks far more convincing. The bigger picture here is that incident response is now a communications problem as much as a technical one. Companies that describe a breach too narrowly in the first 48 hours risk losing credibility just as surely as they risk regulatory action.
Payment-card data and account passwords were not accessed, according to the company, which removes the most immediate route to direct financial fraud. But the stolen profiles are still valuable in the aggregate, because scammers can combine a real name, a real address, a real date of birth and a genuine search term to craft a message that looks entirely plausible. The absence of card data removes one kind of risk while leaving a more insidious social engineering risk intact.
Why It Matters
For consumers, the practical danger is not the data itself but the follow-on contact. A criminal who knows that a person recently searched for 'Asos petite' can write a phishing email or place a call that appears to continue a genuine shopping journey. ASOS has warned customers to be cautious of unexpected messages or calls claiming to be from the company and to never share passwords, security codes or payment details through an unsolicited message or call.
For the wider technology industry, the incident is a reminder that third-party platforms sit inside the trust boundary of the brands that use them. A communication tool, a data warehouse or an analytics layer may be operated by someone else, but the customer experience of a breach is delivered by the retailer. ASOS said its website and app remain safe to use, yet the rogue notification arrived through the app, which shows how difficult it is to separate platform security from brand security in practice.
The episode also lands in a crowded field of retail cyber attacks. With roughly 16.5 million to 17 million customers, ASOS is one of the largest online fashion businesses in the United Kingdom. When a company of that size discloses a breach of names, addresses, phone numbers, emails, customer numbers and dates of birth, the consequences ripple through the fraud economy for months, long after the news cycle moves on.
Next Up
ASOS said it is still investigating, and the immediate next steps will involve regulators, law enforcement and the third parties whose platforms were accessed. The company did not respond to questions about the scale of the breach, and it has not identified the communication platform that was compromised. Whether multi-factor authentication was in place on the affected Snowflake instance is also an open question, and the answer will shape how security practitioners judge the incident.
The hackers, meanwhile, have threatened to leak what they hold if ASOS does not engage. That threat gives the company a difficult set of choices: negotiate, ignore, or continue the investigation while preparing customers for the possibility that more data will surface. For the millions of shoppers who received a message on their own phones telling them the retailer had been hacked, the next notification they open may be one they should not trust.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.