https://www.theguardian.com/business/2026/oct/06/asos-hack-notification-website-app
Asos is investigating unauthorised access to its app notification infrastructure after thousands of customers received push notifications on 6 October claiming the fashion retailer had been fully compromised, with the messages directing users to a Telegram channel operated by a previously unknown group calling itself the Xuanye Group. The retailer confirmed that basic personal information including names and contact details may have been accessed by an unidentified third party but said it did not believe payment card records or passwords had been compromised. Asos took immediate action to restrict access to the affected notification platforms, apologised to customers and advised them to disregard the message and avoid clicking any links contained within it. The company’s website and app continued operating normally with no reported disruption to trading operations, and Asos confirmed it holds cybersecurity insurance including business continuity coverage with a large global provider. Shares on the London Stock Exchange fell more than 14 percent during the day before closing down 9.56 percent, with the company noting it was too early to quantify any potential impact on trading.
The notification sent to customers was addressed to the Asos data protection officer and IT department and stated that the hackers had fully compromised the company’s Snowflake instance. Snowflake is a cloud platform used to store, process and analyse data including transaction records and demographic information such as clothing sizes and body measurements, and also enables push notification delivery to mobile devices. The Xuanye Group’s Telegram channel carried messages telling customers that payment information was not affected and that the app was safe to use, while also indicating that a deadline had been set for Asos, with a post stating that customer data was being held safely and would not be touched for a designated period, a characteristic extortion tactic designed to pressure the company into rapid negotiation. It was noted that there had been no prior record of the Xuanye Group appearing on hacker forums or other Telegram channels. Though that it is not unusual for new groups to wait until they have what they consider a significant opportunity before announcing themselves in order to enter the ecosystem with credibility.
Asos customers to remain vigilant against follow-on phishing attempts that typically exploit the publicity surrounding high-profile breaches, with attackers likely to send emails or messages impersonating Asos and requesting password resets, payment detail confirmation or order checks.