NEWS

ASOS Confirms Data Breach After “HACKED” In-App Notifications

ASOS confirmed a breach after hackers sent unauthorized “ASOS HACKED” push alerts, claiming to have compromised its Snowflake environment.

Dylan H.

News Desk

October 6, 2026
6 min read
ASOS Confirms Data Breach After “HACKED” In-App Notifications

ASOS Confirms Data Breach After “HACKED” In-App Notifications

UK fashion retailer ASOS has confirmed a data breach after a threat actor sent unauthorized push notifications through its mobile app in the early hours of October 6, 2026, claiming to have stolen customer data from the company's Snowflake cloud data environment. ASOS says the notification platform itself — not its core systems or payment infrastructure — was accessed without authorization, and that names and contact details may have been exposed. The retailer has not confirmed the attacker's Snowflake claim, and the incident lands less than three months after ASOS disclosed a separate credential-stuffing breach affecting more than 138,000 customers.


Incident Details

AttributeValue
TargetASOS (asos.com), UK-based online fashion retailer
DisclosureOctober 6, 2026
TriggerUnauthorized “ASOS HACKED” push notification sent via the ASOS mobile app, roughly 5:00 a.m. ET
Confirmed AccessThird-party platform ASOS uses to send customer push notifications
Claimed (Unverified) AccessASOS's Snowflake cloud data warehouse instance
Data Exposed (Confirmed)Basic personal information — names and contact details
Data NOT ImpactedPayment-card information, account passwords
Threat ActorUnidentified; contacted victims via an external Telegram channel linked in the notification
Scale of This IncidentNot disclosed by ASOS
Prior 2026 IncidentCredential-stuffing account takeover disclosed in August 2026, affecting roughly 138,000 customers

What Happened

The unauthorized notification

At approximately 5:00 a.m. ET on October 6, ASOS app users on both iOS and Android began receiving a push notification reading: "ASOS HACKED. Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The message included a link to an external Telegram channel, a hallmark of extortion-style disclosure tactics used by data-theft groups that skip ransomware encryption entirely and instead pressure victims publicly. Multiple recipients flagged the alert to security outlets within minutes of it landing on their phones.

ASOS's response

ASOS confirmed it is investigating "unauthorised activity involving third-party platforms" used to communicate with customers, and has since restricted access to the implicated notification platform. The company pushed an in-app notice instructing customers to disregard the rogue alert and avoid clicking the external link it contained. ASOS says it does not believe payment-card details or account passwords were affected, and described the confirmed exposure as limited to "basic personal information, including names and contact details."

The unverified Snowflake claim

ASOS has not confirmed the attacker's central claim — that its Snowflake instance, which would typically house far more sensitive customer, order, and analytics data than a notification tool, was "fully compromised." Security researchers, including analysts at Check Point, urged caution: gaining unauthorized access to a customer-messaging platform does not by itself demonstrate access to a cloud data warehouse, payment systems, or the wider retail network. Threat actors frequently inflate the scope of what they've stolen to increase extortion leverage and public pressure, and no sample data or independent verification of the Snowflake claim had surfaced at the time of ASOS's statement.

Impact Assessment

Impact AreaDescription
Customer TrustThousands of ASOS app users received an authentic, platform-delivered extortion message, creating confusion and phishing risk
Confirmed Data ExposureNames and contact details accessible via the compromised notification platform
Claimed (Unverified) ExposureBroader customer, order, and analytics data allegedly held in ASOS's Snowflake environment
Financial DataNo evidence to date of payment-card or password compromise
Brand/ReputationSecond publicized ASOS security incident in roughly three months, following the August 2026 credential-stuffing disclosure
Downstream RiskThe embedded Telegram link could be weaponized for follow-on phishing if customers engage with it directly

Recommendations

For ASOS and its security team

  • Rotate and audit all API keys, service accounts, and OAuth tokens tied to the compromised notification platform, since push-delivery credentials often sit alongside other secrets in the same cloud tooling.
  • Independently verify — or formally rule out — the attacker's Snowflake compromise claim, including a review of query logs, data-sharing configurations, and any third-party integrator with standing access to the warehouse.
  • Enforce multi-factor authentication and network-policy restrictions on all Snowflake account access, consistent with the vendor's post-2024 guidance issued after the wider Snowflake customer breach wave.
  • Publish a follow-up disclosure with a confirmed scope once the investigation concludes, given the ambiguity in the initial statement.

For retail and e-commerce security teams generally

  • Treat customer-communication tooling (push, email, SMS) as a privileged system, not a low-risk marketing add-on — it has direct, trusted access to your entire user base.
  • Audit which vendors and SaaS integrators hold live credentials to your data warehouse, and require short-lived, scoped tokens rather than long-lived static keys.
  • Build a rapid-response playbook for "authentic-channel" abuse, where attackers use your own legitimate notification system to reach customers directly.

For ASOS customers

  • Do not click the link in the “ASOS HACKED” notification or any similar unsolicited alert; report it in-app and delete it.
  • Watch for follow-up phishing attempts referencing this incident, especially messages asking you to "verify your account" or "confirm your Snowflake data."
  • Use a unique, strong password for your ASOS account and enable any available multi-factor authentication, particularly if you reused credentials affected in ASOS's August 2026 breach.
  • Monitor bank and card statements as a precaution, even though ASOS says payment data was not impacted in this incident.

Key Takeaways

  1. ASOS confirmed a breach after a threat actor sent unauthorized “ASOS HACKED” push notifications to app users around 5:00 a.m. ET on October 6, 2026.
  2. The notification claimed a "full compromise" of ASOS's Snowflake instance and threatened to leak data; ASOS has not confirmed this claim.
  3. ASOS confirmed only that a third-party customer-notification platform was accessed without authorization, exposing names and contact details — not payment-card data or passwords.
  4. The threat actor directed victims to an external Telegram channel, a pattern consistent with extortion-focused data-theft groups rather than ransomware operators.
  5. This is ASOS's second publicized 2026 security incident, following an August-disclosed credential-stuffing breach that affected roughly 138,000 customers; no link between the two incidents has been established.
  6. The Snowflake claim echoes the 2024-2025 wave of Snowflake-customer extortion attacks (Ticketmaster, Neiman Marcus, Advance Auto Parts) that relied on stolen credentials rather than a platform vulnerability — but unlike those cases, ASOS's Snowflake exposure remains unverified.

Sources