Opens in a new tab

ASOS Hack Alert: What the Threatening Message Means

Unverified claim of ASOS hack and threatening customer notifications

An apparent ASOS hack sent a threatening push notification to customers through the retailer’s official mobile application on 6 October 2026. The message claimed that company data had been compromised, but ASOS had not confirmed a breach or data theft at the time of reporting.

The incident is unusual because the hostile message appeared through a trusted customer communication channel rather than email or SMS. Although the alert demonstrates unauthorised use of the app’s notification capability, it does not by itself prove that attackers accessed ASOS customer records or its claimed Snowflake environment.

What happened in the ASOS hack alert

At approximately 10:01 BST on 6 October 2026, ASOS app users received a push notification titled “ASOS HACKED”. The message was addressed to the retailer’s data protection officer and IT team, suggesting it was intended as a public extortion message rather than a conventional customer notification.

The sender claimed that ASOS’s “Snowflake instance” was fully compromised and warned the company to make contact or face a data leak. Recipients were directed to a Telegram channel, which one report identified as “Xuanye Gateway”. The channel name should be treated as an unvalidated indicator because no official technical advisory has linked it to a confirmed threat group.

Thousands of customers reportedly received the notification. Multiple users shared images of the alert, while widespread reporting confirmed that it had appeared through the official ASOS app. Reports specifically identified iOS recipients, although no complete breakdown of affected device types was available.

The threatening wording triggered immediate concern among customers and investors. ASOS shares fell by approximately 11 to 13 per cent during morning trading, demonstrating the financial and reputational effect that abuse of a high-profile notification channel can cause before the underlying claims are verified.

ASOS hack timeline on 6 October 2026

The incident developed quickly during the morning of 6 October. The known sequence of events is:

  • At about 10:01 BST, the hostile push notification appeared on customer devices through the official ASOS mobile application.
  • At 10:09 BST, the first public reports described the “ASOS HACKED” alert, its reference to Snowflake and the link to Telegram.
  • At 10:52 BST, reports said ASOS shares had fallen by more than 10 per cent following news of the alert.
  • At 11:16 BST, further coverage repeated the notification text and documented the continuing effect on the company’s share price.
  • Between 11:38 and 11:54 BST, reports said thousands of customers had received the message. ASOS was aware of the reports but had not confirmed a breach.

User-reported problems also rose on Downdetector around the time of the notification. However, the ASOS website and mobile application remained accessible, and there was no confirmed widespread interruption to shopping or account services.

How the hostile ASOS notification may have been sent

The confirmed technical fact is that somebody obtained the ability to deliver a hostile message through the ASOS app’s push notification channel. Push notifications normally pass through an organisation’s application infrastructure and the notification services operated by mobile platform providers.

Possible routes could include unauthorised access to an administrative console, exposed credentials, compromised API keys or access to a third-party communications platform. These remain possibilities rather than confirmed explanations. No technical evidence identifying the exact entry point, affected account or exploited vulnerability had been published.

The notification’s appearance through the official app makes the event different from ordinary brand impersonation. A conventional phishing message may imitate a company from an unrelated email address or website. In this incident, the message reached devices through a channel that customers would reasonably associate with ASOS, giving it immediate credibility and visibility.

However, access to push delivery does not necessarily provide access to customer databases. Notification systems can be separate from retail, payment, identity and data warehouse environments. The ASOS hack claim concerning Snowflake therefore requires independent verification.

The unconfirmed Snowflake claim

The attackers asserted that ASOS’s Snowflake instance was fully compromised. No statement from ASOS or Snowflake had confirmed that ASOS operated the claimed environment, that it had been accessed or that information had been extracted.

No samples of allegedly stolen data, file listings or other evidence of exfiltration were reported. There was also no public exploit code associated with the incident. The Telegram link appears to have been provided as a contact route for the alleged extortion attempt, not as proof of access.

Who and which products are affected

The directly affected product was the ASOS mobile application’s push notification channel. Reports documented the alert on iOS devices, but they did not identify specific ASOS app versions, iOS builds or Android versions. It is therefore not possible to define exposure according to a particular software release.

Customers who received the notification were exposed to a threatening message and a Telegram link. There was no confirmed evidence at the time of reporting that receiving or viewing the notification compromised a device. Users should nevertheless avoid following the link or engaging with the referenced channel.

The threat actor remains unattributed. The reported “Xuanye Gateway” name is not enough to establish who controlled the notification system, whether the same party accessed any other ASOS environment, or whether the Snowflake claim was genuine.

What is confirmed and what remains unknown

The in-the-wild abuse of the app notification channel is confirmed by customer reports and widespread coverage. The message’s title, extortion wording, Snowflake reference and Telegram direction were consistently documented.

By contrast, the central data breach claim remains unverified. ASOS had not confirmed unauthorised access, data theft or a compromise of Snowflake by the latest reports at 11:54 BST. No IP addresses, domains, file hashes or host artefacts had been released for defenders to investigate.

The continuing availability of the website and app also means this was not a confirmed service-disruption attack. The observed operational effects were the customer-facing notification, increased outage reports, extensive publicity and a sharp movement in ASOS’s share price.

Why the ASOS hack alert matters

This event shows how control of a trusted broadcast channel can create an immediate crisis without public proof of data theft. Mobile push systems can reach large audiences within seconds, while an extortion message can drive customer concern, media attention and financial consequences before an organisation has established the scope of an incident.

There is also a risk of secondary scams. Criminals may exploit publicity around the ASOS hack by sending fake password resets, refund offers or breach notifications that direct recipients to credential-stealing websites.

Actions organisations and customers should take

  • Organisations should review access logs, administrator activity, API keys and third-party integrations associated with mobile push services.
  • Privileged notification accounts should be restricted and protected with phishing-resistant multi-factor authentication where supported.
  • Customers should not follow the Telegram link or respond to messages claiming to represent the attackers.
  • Unexpected ASOS emails, password prompts or refund messages should be verified through the official app or website.
  • Security teams should monitor for copycat domains and phishing campaigns that reuse the wording of the alert.

Customers should wait for verified information before assuming their personal data has been stolen. Any later confirmation from ASOS, Snowflake or a regulator will be necessary to determine whether this was limited to notification infrastructure or formed part of a wider compromise.

Originally reported by TechRadar.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call