ASOS has confirmed unauthorized access to third-party customer-communications platforms after customers received a threatening message through the retailer’s official mobile app.
The incident became public on October 6, 2026, when BleepingComputer reported the unauthorized notifications and ASOS’s response. According to the publication, alerts began appearing at approximately 5:00 a.m. ET on Tuesday. A separate date for the start of the underlying access was not provided.
ASOS said basic personal information, including customer names and contact details, may have been exposed. The company does not believe payment-card information or account passwords were affected.
The number of customers whose information may have been compromised remains unspecified. Likewise, the number of people who received the rogue notification has not been established.
A threatening message arrived through the official ASOS app
Customers reported receiving an alert labelled “ASOS HACKED” from the legitimate ASOS mobile application. BleepingComputer said multiple readers contacted the publication about the message, while additional customers described the same alert on Reddit.
The notification alleged that ASOS had suffered a complete compromise of its Snowflake environment. It threatened publication of data unless the retailer communicated with the sender and directed recipients to a Telegram channel.
That channel was associated with a group calling itself Xuanye group.
The use of an official app notification channel gave the message greater apparent legitimacy than an ordinary phishing email or unsolicited text. However, receiving the alert through the ASOS app does not by itself establish that attackers compromised the app, its source code or customer devices.
ASOS attributed the activity to unauthorized access involving third-party platforms used to communicate with customers. The company did not identify those providers or describe the technical path used to send the notification.
Customer reports suggested broad distribution, potentially reaching many mobile-app users. That observation is not a verified recipient count, and it does not prove that every ASOS app user received the message.
ASOS identifies possible exposure of names and contact details
In its statement, ASOS acknowledged that third-party customer-communications platforms had been accessed without authorization. The retailer said the incident may have exposed basic personal information, including names and contact details.
ASOS did not specify which types of contact information were involved. It also did not disclose how many customers may be affected or provide a record count. Those are separate measurements: one person can be associated with multiple database records, while a notification recipient is not necessarily someone whose personal information was exposed.
The company said it did not believe payment-card details or account passwords were affected. That statement defines ASOS’s current assessment; it is not an independent confirmation of the full contents of any data accessed by the intruders.
The confirmed scope is therefore narrower than the attacker’s message. ASOS has acknowledged unauthorized access to communications platforms and possible exposure of basic customer information, but it has not confirmed a compromise of its Snowflake environment.
Xuanye group’s broader claims remain unverified
Xuanye group later claimed it had stolen customer information. In the material described by BleepingComputer, however, the group did not identify the allegedly stolen data, quantify the affected customer population or provide evidence supporting its Snowflake allegation.
The group initially stated that payment information was not affected. It also told users that the app remained safe and made claims about keeping the data secure on its own server for a specified period.
Those statements come from the party claiming responsibility and have not been independently demonstrated. In particular, an attacker’s promise concerning the storage, use or future disclosure of data should not be treated as a security guarantee.
BleepingComputer said it attempted to contact the operators. The available contact mechanism required payment, and the publication did not pay for information.
There are consequently two distinct scopes to track:
- Confirmed by ASOS: unauthorized access to third-party customer-communications platforms, with possible exposure of names and contact details.
- Alleged by Xuanye group: theft of customer information and compromise of ASOS’s Snowflake environment.
The available reporting does not bridge that evidentiary gap. It also does not establish whether the unauthorized notification capability and the possible personal-data exposure resulted from the same access path.
The notification channel itself created an immediate risk
The direct customer-facing consequence was the delivery of an attacker-controlled message through a trusted channel. The alert contained an external link leading away from the ASOS app and toward the group’s Telegram presence.
ASOS responded with an in-app warning telling customers to disregard the unauthorized alert and not to click or otherwise interact with its link. That is the company’s principal customer guidance reported so far.
Even without confirmed exposure of passwords or card details, names and contact information can make subsequent fraudulent messages more convincing. Customers should therefore treat unexpected communications claiming to concern the incident with caution, particularly if they demand payment, request credentials or direct users to external messaging services. This is a risk assessment based on the categories of information ASOS said may have been exposed, not evidence that such follow-on activity has occurred.
The rogue alert should not be interpreted as proof that a recipient’s individual account was accessed. Conversely, receiving no alert would not establish that a customer’s information was outside the potentially exposed data.
What ASOS customers should do now
Customers who saw the “ASOS HACKED” notification should follow ASOS’s instruction: ignore it and avoid opening or interacting with the external link.
Any later message about the incident should be checked through ASOS’s official app or website rather than through links supplied in push notifications, emails, text messages or Telegram posts. Customers should not provide account credentials, payment details or verification codes in response to unsolicited communications.
ASOS currently says it does not believe account passwords or payment-card information were affected. The reported response therefore does not include a company instruction requiring all customers to reset passwords or replace cards.
The report also provides no further technical remediation information, such as the names of the accessed communications platforms, containment measures, indicators of compromise or security updates. It does not give a schedule for notifying potentially affected individuals.
Until ASOS supplies a more detailed scope, customers face two confirmed practical issues: an unauthorized message was delivered through the retailer’s app notification channel, and basic personal information may have been exposed. Claims of a wider Snowflake compromise remain allegations rather than established facts.




