ASOS confirms unauthorised push alert and probes Snowflake breach claim
According to Malwarebytes, thousands of ASOS customers received a push notification through the retailer’s app on October 6, 2026, claiming the company had been hacked. ASOS has confirmed that an unauthorised customer notification was sent and says it is investigating, but the claimed theft of data from a Snowflake instance has not been confirmed. This ASOS data breach report is still developing.
What we know about the ASOS data breach claim
- The push message was addressed to ASOS’s data protection officer and IT team. It claimed the attackers had “fully compromised the Snowflake instance” and demanded contact, or the data would be leaked.
- Sky News reports that ASOS confirmed an “unauthorised customer notification” went out at around 10 am. ASOS said it is investigating unauthorised activity involving third-party platforms used to communicate with customers.
- ASOS says it immediately restricted access to the notification platforms and is working with specialists and relevant authorities.
- The Guardian reports that the group claiming responsibility calls itself the “Xuanye group”. Its Telegram channel said payment information was not affected and the app is safe to use. Those statements have not been independently verified.
Who is affected
Customers who received the notification were clearly exposed to the unauthorised message. Whether any stored data was accessed is not yet established.
ASOS said basic personal information, such as name and contact details, may have been accessed. It does not believe payment-card information or account passwords were affected.
Snowflake is a cloud data platform. Malwarebytes notes that ASOS’s marketing team uses Simon AI, a personalisation product that runs on Snowflake, alongside Braze to trigger customer communications such as push notifications. Simon AI describes typical customer profiles as covering browsing and purchase history, customer value, demographic segments and geolocation. If ASOS’s systems hold such profiles, a breach could expose a detailed picture of shopping habits. Malwarebytes stresses that the published description of the setup does not show what, if anything, was accessed.
What has not been confirmed
- That a Snowflake instance was compromised. This is the attackers’ claim only.
- That any customer database was stolen. Malwarebytes says there is currently no verified evidence of this.
- The attackers’ statements about payment data and app safety.
- How the attackers gained access to the notification tooling. ASOS has only referred to third-party platforms; the specific platform and method have not been disclosed.
Why this matters
Analysis, not new facts. A message delivered through a retailer’s own app is more convincing than a social-media claim, because it shows someone was able to use trusted messaging infrastructure. It points towards compromised access to the marketing or notification stack, such as an account, API credential or integration, rather than the app itself, though the sources do not confirm the cause.
For defenders, the lesson is that customer-engagement platforms are privileged systems. They can reach every user, and they often connect to a data warehouse holding profile data. They deserve the same controls as other administrative tools.
How to protect yourself after the ASOS notification
For ASOS customers:
- Treat unsolicited messages about the incident, or other ASOS issues, with suspicion. Stolen contact details could be used to make phishing more convincing.
- Do not click links in messages claiming to be about the breach. Go to the official site or app directly.
- Malwarebytes suggests holding off on purchases until ASOS clarifies what happened, and removing the app if you do not want further messages from the attackers.
- Watch for ASOS’s own notices and follow its guidance on any data exposure.
What security teams should do
- Audit who and what can send push, email or SMS campaigns, including service accounts and API keys. Rotate credentials and enforce MFA and IP restrictions where possible.
- Review access to any data warehouse, such as Snowflake, that feeds marketing tools. Check for unusual logins, new integrations and large exports.
- Alert on campaign sends that were not scheduled or approved through the normal workflow.
- Prepare a customer-communication plan for a rogue-notification event, including how to confirm the legitimate channel.
- Brief your support and fraud teams that phishing referencing a breach is likely to follow such incidents.
We will update this story if ASOS or the investigators publish further confirmed details.
