Skip to main content
Emerging ThreatsData Breaches

ASOS Breach Exposes Customer Data After Hackers Compromise App

Smartphone screen displays hacked notification on neutral surface.

"ASOS HACKED," reads the notification seen by BleepingComputer.

“ASOS HACKED” push notifications hit mobile app users

Shortly after 5:00 a.m. ET on Tuesday, mobile users of the ASOS app began receiving unauthorized push alerts that read "ASOS HACKED," directing recipients to an external link. Multiple BleepingComputer readers reported receiving the same alert, and numerous customers posted the message on Reddit, indicating the notification reached many, if not all, app users.

The in-notification text included a direct address to ASOS's data protection and IT functions: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification routed recipients to a Telegram channel operated by a threat actor calling itself the "Xuanye group."

Claims about ASOS’s Snowflake environment and customer data

The group behind the Telegram channel initially claimed the incident did not affect payment information. Later messages published as a "FINAL STATEMENT" escalated the claim, saying they had stolen customer information. In that final message the group wrote: "The affected organisation's app is safe to use. The incident involves customer information, it is safe on our server, and it will not be touched for a designated period." The same message added, "Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident."

Despite those public statements, the threat actor did not disclose what customer information was allegedly taken, how many customers were affected, or publish evidence showing it had compromised ASOS's Snowflake environment.

ASOS confirmation: third-party communications platform accessed

ASOS confirmed that third-party platforms used to communicate with customers were accessed without authorization. The company said basic personal information — explicitly including names and contact details — may have been exposed as a result of that unauthorized access.

ASOS also posted an in-app notice instructing customers to disregard the unauthorized push alert and not to click or engage with the external third-party link it contained. The company said it does not believe payment-card information or account passwords were impacted. ASOS has not confirmed the Xuanye group's claim that its Snowflake environment was compromised, nor has it disclosed how many customers may be affected.

The Xuanye group’s public posture and BleepingComputer’s contact attempt

The Telegram channel credited to the Xuanye group served as the central point of the group's public messaging. After moving from an initial denial that payment data was affected to a later assertion that customer information had been stolen, the group provided no verifiable proof in public posts.

BleepingComputer attempted to contact the threat actors for comment, but the attackers required payment to continue communication. BleepingComputer did not pay, citing its editorial guidelines.

What this means for technologists, ASOS customers, and communications providers

  • Technologists and security teams: The incident highlights an unauthorized access vector through third-party customer-communication platforms; security teams will watch vendor integrations and control planes used to send push notifications.
  • ASOS customers (end users): Customers have been asked by ASOS to disregard the push alert and not to follow the external link; the company has stated that names and contact details may have been exposed but that payment-card data and account passwords are not believed to be affected.
  • Third-party communications providers: The company's confirmation that third-party platforms were accessed without authorization points to those vendors as focal points for investigation and mitigation, and as likely subjects of scrutiny by ASOS and any investigating parties.

For those with additional information about the incident or other undisclosed attacks, BleepingComputer listed confidential contact options: a Signal number, 646-961-3731, and an email, tips@bleepingcomputer.com.

ASOS's public disclosures confirm an unauthorized access to customer-communication channels and flag possible exposure of basic personal information, while the attackers' public statements claim a far larger compromise without supplying evidence. That gap — between the threat actor's assertions about Snowflake and stolen data and ASOS's narrowly framed confirmation regarding third-party platforms — is the central, verifiable fact of the incident. Whether further proof appears, how many customers were affected, and whether ASOS's Snowflake instance was involved remain unresolved by the material published to date.

Original reporting: BleepingComputer — ASOS confirms data breach after “HACKED” in-app notifications