ASOS has confirmed a cybersecurity incident after attackers gained unauthorized access to third-party systems used to communicate with customers and sent a threatening notification through the retailer’s official mobile app.
The incident became public on October 6 when customers received an unexpected push notification claiming that ASOS had been hacked. The message was addressed to the company’s data protection officer and IT team and threatened to leak stolen information unless ASOS contacted the attackers.
ASOS later confirmed that the notification was unauthorized and said it immediately restricted access to the affected communication platforms. The company is working with internal and external cybersecurity specialists as well as relevant authorities to determine the full scope of the incident.
Basic customer information, including names and contact details, may have been accessed. However, ASOS currently does not believe that payment-card information or customer account passwords were compromised.
The group claiming responsibility calls itself Xuanye Group. In its notification, the attackers claimed they had fully compromised ASOS’s Snowflake environment, but ASOS has not confirmed that claim or revealed how many customers may have been affected.
Snowflake launched its own investigation after learning about the incident and said it had found no evidence that its platform itself had been compromised. This leaves open the possibility that the incident involved customer-specific credentials or another third-party service rather than a security failure affecting Snowflake more broadly.
ASOS has added a warning inside its app telling customers to ignore the unauthorized notification and avoid interacting with the external link it contained. The retailer is not currently asking customers to change their passwords or take other specific action.
The company’s website and mobile app continue to operate normally, and ASOS says customers can continue shopping. UK cybersecurity authorities nevertheless recommend that ASOS customers remain alert for suspicious emails, texts and other messages that could use exposed contact information to make phishing attempts more convincing.
ASOS has not yet disclosed how the attackers accessed its communication systems or confirmed exactly how much customer information was exposed. The investigation remains ongoing.
