
British online fashion retailer Asos has confirmed a data breach involving customers’ personal information after hackers used its mobile app to send threatening notifications. The company disclosed the incident on October 8, 2026, stating that attackers accessed third-party platforms used for customer communications and obtained names and contact information.
According to BBC News, the stolen information also includes home addresses, telephone numbers, email addresses, and customer profile notes, including website search queries. Asos has approximately 17 million customers worldwide, although the company has not disclosed how many were affected.
Hackers Use Asos App to Threaten Data Leak
On October 6, customers received unauthorized push notifications through the official Asos app, with many sharing screenshots on social media. The messages were addressed to the company’s data protection officer and IT department, claiming its data stored on Snowflake had been compromised.
The notification warned that the hackers would publish the stolen information unless Asos contacted them. The attackers identified themselves as Xuanye Group but have not disclosed how much customer data they allegedly possess.
Snowflake provides cloud-based data storage and analytics services to businesses, including retailers. The company said its own systems had not been breached, although the hackers claimed to have accessed an Asos-related Snowflake environment.
Attackers Obtained Employee Login Credentials
According to BleepingComputer, the attackers gained access by impersonating a trusted contact and convincing an Asos employee to disclose login credentials. They subsequently used those credentials to access information stored on third-party platforms.
The technique, known as social engineering, involves manipulating individuals into revealing confidential information or granting unauthorized access. It remains unclear whether the affected Snowflake account had multi-factor authentication enabled or how the hackers accessed Asos’ push notification system.
Asos said its investigation found no evidence that payment card information or customer account passwords were compromised. The retailer has secured the affected platforms and is working with external cybersecurity specialists, law enforcement, and regulators.
Asos Advises Customers to Watch for Suspicious Messages
Asos said its website and mobile app remain safe to use and that customers do not need to make immediate changes to their accounts. However, the company advised users to remain cautious of unexpected messages or calls claiming to represent Asos, particularly requests for passwords, security codes, or payment details.
A similar incident occurred in January 2026 when financial technology company Betterment confirmed that attackers had compromised a third-party marketing platform. The attackers accessed customer information and used the company’s notification system to send fraudulent cryptocurrency promotions.
Featured image credits: Google Play
For more stories like it, click the +Follow button at the top of this page to follow us.
