Asos has confirmed a breach of customer data after hackers used the retailer’s own app notification system to warn users that the company had been compromised. The U.K. fashion giant said the intrusion involved a third-party platform it uses to communicate with customers, and that names and contact information were taken in the incident.
What Asos says was taken
In a filing with the London Stock Exchange, Asos said hackers broke into a third-party system hosting data used for customer communications. The company said the stolen information included names and contact details, while BBC News reported that the exposed data also covered home addresses, phone numbers, email addresses, and notes tied to customer profiles, including website search queries.
Asos has not said how many customers were affected or how much information was accessed. The retailer said it has 17 million customers, according to its website.
Hackers used Asos’ own app to send a warning
The breach became public after customers received an “unauthorised customer notification” through the Asos app, which many users then shared on social media. The message was addressed to Asos’ data protection officer and IT department and claimed the attackers had “fully compromised” data hosted on Snowflake, the data platform used by the company.
The notification also contained a threat: “Engage with us, or we will leak it.” That tactic appears designed to pressure the company into opening a dialogue while also signalling that the attackers may publish stolen material if their demands are ignored.
Snowflake platform involvement remains under review
According to reporting from Bleeping Computer, the attackers allegedly got into the Snowflake instance by “impersonating a trusted contact to obtain log in credentials.” Snowflake said it had not experienced a breach of its own systems. It remains unclear whether the Asos instance was protected with multi-factor authentication.
It is also not known how the attackers gained access to the system used to send in-app push notifications, which is commonly handled by a third-party service rather than the app operator itself. That makes the incident a reminder that customer communication tools can become a powerful channel for abuse when they are connected to sensitive internal systems.
Who is behind the incident?
The hackers have been identified by the handle Xuanye Group, but they have not said how much data they claim to possess. Their use of a company-branded notification system to publicize the breach is unusual, but it fits a growing pattern in which attackers use stolen access not only to exfiltrate data, but also to amplify pressure on the victim.
In this case, the choice of channel matters. A notification that appears to come from the retailer itself is more likely to be noticed by customers than an email buried in spam or a message posted on a leak site after the fact.
Why this breach stands out
Data breaches often spread through email, customer portals, or internal records, but Asos appears to have been hit at the intersection of marketing, cloud data handling, and customer communications. That combination can increase the damage because attackers may obtain personal information and then use legitimate-looking systems to reach the same people.
- Customer data involved: names, contact information, and reportedly home addresses, phone numbers, email addresses, and profile notes.
- Attack path: access to a third-party platform used for customer communications and, reportedly, a Snowflake instance.
- Public pressure tactic: an unauthorised notification sent through Asos’ own app.
- Attribution: attackers operating under the name Xuanye Group.
Part of a wider pattern
Asos is not the only company to face abuse through third-party platforms. Earlier this year, fintech company Betterment was compromised through access to a third-party marketing platform, which was then used to impersonate the company and send a crypto scam to customers. In that incident, attackers also accessed customer names, email addresses, phone numbers, and other data.
The common thread is that even when a company’s core systems are not directly breached, linked services can still expose personal data and become tools for deception. That makes vendor oversight, authentication controls, and access monitoring just as important as the security of the main corporate network.
What customers should watch for
Asos has not disclosed whether affected customers have been directly contacted beyond the app notification incident itself. Still, people who shop with the retailer should be alert to phishing attempts that use real personal details to sound convincing.
Useful precautions include:
- Checking whether any message about the incident comes from an official Asos channel.
- Being cautious with emails or texts asking for logins, payment details, or account verification.
- Watching for signs of targeted phishing that references recent purchases or browsing habits.
- Updating passwords if account credentials were reused across services.
The company has not said whether it has contained the incident or how it is working with the hackers’ claims. For now, the confirmed breach adds another example of how customer-facing systems can be turned into both an entry point and a megaphone for attackers.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: October 8, 2026 at 10:31 pm
0 views

