ASOS CONFIRMS CYBER INCIDENT AFTER ATTACKERS HIJACK CUSTOMER NOTIFICATION PLATFORM

ASOS confirmed on October 6, 2026, that unauthorized activity affected third-party platforms used to communicate with customers, enabling an unidentified party to send an unauthorized notification through the retailer’s official channels.

The UK-based online fashion retailer said basic personal information, including customer names and contact details, may have been accessed. ASOS does not currently believe payment-card information or account passwords were affected.

The incident is notable not only for the potential data exposure, but also because the attackers apparently weaponized a trusted customer-notification channel to deliver an extortion message directly to shoppers.

ATTACKERS USED ASOS’S OFFICIAL CHANNEL TO ANNOUNCE THE BREACH

At approximately 10 a.m. on October 6, customers received a push notification titled “ASOS HACKED.” The message claimed that attackers had fully compromised the company’s Snowflake instance and threatened to leak data unless ASOS contacted them through Telegram.

ASOS subsequently confirmed that the notification was unauthorized. The company said it immediately restricted access to the affected notification platforms and began working with internal and external security specialists and relevant authorities.

The company’s website and mobile application remained operational, with no reported interruption to ordering or other business functions. ASOS also said it was too early to quantify any effect on trading.

WHAT ASOS HAS VERIFIED

ASOS has verified three important elements of the incident:

  • An unauthorized party accessed activity involving third-party customer-communication platforms.
  • An unauthorized notification was sent to ASOS customers.
  • Names and contact information may have been accessed.

The company has not confirmed how many customers were affected, how the intruder obtained access, which service providers were involved, or whether information was exfiltrated.

ASOS also has not verified the attacker’s claim that its Snowflake environment was fully compromised. That claim should therefore be treated as an allegation, not an established technical finding.

Similarly, the previously unknown group calling itself “Xuanye” has claimed responsibility, but its identity, capabilities and involvement have not been independently established.

Leave a Comment

Your email address will not be published. Required fields are marked *