ASOS Customers Receive Hack Warning Through Retailer’s App

A fashion and pop culture writer who watches a lot…
ASOS is investigating a potential cyberattack after customers received an hacked notification via the mobile app claiming that the fashion retailer’s data had been compromised. The notification, sent to shoppers in several countries, said attackers had “fully compromised” an ASOS Snowflake instance and threatened to leak information if the company did not engage with them.
The message appeared directly on customers’ phones through ASOS’s notification system, raising concerns among cybersecurity experts about how an alleged attacker gained access to the retailer’s communication infrastructure. The notification also included a link directing recipients to a Telegram channel apparently operated by a group calling itself Xuanye.
ASOS Investigates Unauthorized Activity
ASOS has been hacked, according to a notification sent to users. https://t.co/p1TDAllx0I
— Pop Base (@PopBase) October 6, 2026
ASOS said it was investigating unauthorized activity involving third-party platforms used to communicate with customers. The company said it had taken immediate action to restrict access to the notification platforms and was working with internal and external specialists, as well as relevant authorities.
The retailer said its website and app were operating normally and that there had been no disruption to its operations. ASOS also said basic personal information, including names and contact details, may have been accessed by an unidentified third party, but it did not believe payment-card information or passwords had been compromised.
“Customer trust is incredibly important to us,” the company said, adding that it would provide an update if the situation changed.
Hackers Target ASOS Customers With Message
Payment info in the ASOS attack is allegedly not affected (if you trust attackers) but I would probably agree with that due to the Snowflake cloud data being the target https://t.co/wt0RYyoGh1
— Jake Moore (@JakeMooreUK) October 6, 2026
The notification was headed “ASOS HACKED” and appeared to be addressed to the retailer’s data protection officer and IT department. It claimed that the attackers had gained access to a Snowflake instance and warned the company to engage with them or face a leak.
The message was particularly notable because it appeared to have been delivered through ASOS’s own customer notification system rather than through an external hacking forum. Marijus Briedis, chief technology officer at NordVPN, described the method as concerning because it suggested that someone had gained unauthorized access to at least part of the retailer’s systems.
The link included in the notification directed customers to a Telegram channel apparently operated by the purported attackers. The group, which calls itself Xuanye, had not previously been widely identified in hacker forums or other Telegram channels, according to cybersecurity researchers.
Snowflake Named In The Alleged Attack
The notification’s reference to Snowflake has drawn additional attention because the cloud data platform is used by major companies to store and analyze large amounts of information. Snowflake has previously been linked to investigations into cyberattacks involving companies including Ticketmaster and AT&T.
However, the reference does not establish that Snowflake itself was breached or that ASOS customer data was stolen. Investigators are still working to determine how the notification was sent and what systems, if any, were accessed.
The National Cyber Security Centre, part of the UK’s GCHQ intelligence agency, has offered assistance to ASOS as the investigation continues.
ASOS Shares Fall Following Customer Notifications
Asos share price now down 10%. Perhaps that was even the purpose of the hack. https://t.co/uSc2tZVyg9
— dan barker (@danbarker) October 6, 2026
News of the notification sent ASOS shares sharply lower on the London Stock Exchange. The company’s stock initially fell by more than 14% before recovering some of those losses after ASOS confirmed that it had cybersecurity insurance, including business continuity coverage.
The company has warned, however, that it is too early to quantify any potential impact on trading.
The reaction reflects the growing financial consequences of cyber incidents for retailers whose businesses depend heavily on online systems. ASOS operates digital stores across multiple international markets, meaning any significant disruption could potentially affect both customers and the wider business.
Cybersecurity Experts Warn Of Phishing Attempts
Security specialists have also warned ASOS customers to be cautious about follow-up messages. Dray Agha, senior manager of security operations at Huntress, said the decision to send the alleged ransom demand directly to customers was an aggressive extortion tactic and advised shoppers to remain alert for targeted phishing attempts.
Marijus Briedis similarly warned that criminals could exploit the publicity surrounding the incident by sending emails or text messages pretending to be from ASOS. Such messages could ask customers to reset passwords, confirm payment information, check an order or claim a refund.
Customers are therefore being advised not to click suspicious links or provide personal or financial information in response to unexpected messages.
A Growing Problem For UK Retailers
🇬🇧 MARKS & SPENCER GOT HACKED – CUSTOMER INFO STOLEN, WEBSITE STILL BROKEN
M&S – the super British store your gran loves – has been getting wrecked by a cyberattack for over 3 weeks.
Online orders have been down since April, and now they’ve admitted: yep, some customer info got stolen too. (No card numbers or passwords, though… apparently.)
Hackers likely pulled a ransomware move: lock the systems, demand cash, chaos ensues.
Meanwhile, M&S is losing millions and missing out on selling swimsuits while the UK actually has summer weather for once.
Source: Reuters
— Mario Nawfal (@MarioNawfal) May 13, 2025
The potential ASOS breach comes after a series of cyber incidents affecting major UK retailers. Marks & Spencer, the Co-op and Harrods have all faced cyberattacks, with some incidents causing significant disruption to their operations.
For ASOS, the incident highlights the risks created by an increasingly interconnected retail infrastructure in which websites, apps, cloud platforms and third-party services work together to deliver the shopping experience.
For now, ASOS’s website and app remain operational as the company investigates what happened. The key questions are whether customer information was actually taken, how the attackers gained access to the notification system and whether the claims made in the ASOS hacked app message accurately reflect the extent of the incident.
Featured image: Casimiro_PT/Deposit Photos
—Read Also
A fashion and pop culture writer who watches a lot of TV in his spare time. At Style Rave, we aim to inspire our readers by providing engaging content to not just entertain but to inform and empower you as you ASPIRE to become more stylish, live smarter and be healthier.

