Customers of the British fashion retailer Asos opened their phones around 10 a.m. on Oct. 6, 2026, to a push notification from the Asos app itself that was addressed not to shoppers but to the company’s data protection officer and IT staff. It declared the retailer’s Snowflake instance “fully compromised” and demanded that Asos engage with the senders or face a leak of the data.
A group calling itself Xuanye Group claimed responsibility on Telegram. Asos confirmed an unauthorised customer notification, said basic personal information may have been accessed, and said it does not believe payment-card details or account passwords were affected.
A ransom note delivered through the app
The notification travelled through Asos’s own messaging system, which is why it carried weight. A fake text or email can be dismissed as phishing, but an alert from the retailer’s own app arrives with the app’s authority. Malwarebytes reported that thousands of customers received the alert, headed “ASOS HACKED,” and that it landed through the retailer’s own notification infrastructure, a sign that someone had gained access to the communication tooling. The same report said Asos uses Snowflake to store customer profiles that include browsing history, purchase data, demographics and location information, and it advised readers to treat unsolicited breach-related messages with skepticism. Engadget described the same message and the Snowflake claim, and noted that Snowflake is the cloud service the attackers said they had breached, which handles transaction and customer demographic data.
The Xuanye Group’s Telegram post said payment information was not affected and the app was safe to use, according to Hackread, which described the group as previously unknown. Those statements are the group’s own and have not been independently verified.
Asos’s statement and Snowflake’s response
Asos’s statement, as quoted by Hackread and Cyber Magazine, says the retailer is investigating unauthorised activity involving third-party platforms used to communicate with customers, and that “basic personal information including name and contact details may have been accessed.” The company said its app and website kept running normally, restricted access to the affected notification platforms and is working with cybersecurity specialists and authorities. Hackread added that the UK’s National Cyber Security Centre is assisting.
The Snowflake name in the message needs careful reading. Hackread reported that Snowflake itself found no evidence that its platform had been compromised, and that the group claimed access to an Asos customer environment hosted there. Asos has not identified which third-party platforms were involved or how many customers received data-exposure warnings, and none of the reporting reviewed gives a count of affected accounts.
The 2024 Snowflake campaign as a yardstick
Snowflake became a byword for extortion in 2024, when a campaign hit roughly 165 organizations. Google Cloud’s Mandiant team, in its report on the group it tracks as UNC5537, found that every incident traced to stolen customer credentials from infostealer malware, not to a breach of Snowflake’s own infrastructure. The report found that at least 79.7% of the accounts the attackers used had prior credential exposure, with some stolen logins dating to 2020, and it named infostealer families such as Vidar, RisePro, Redline, Raccoon Stealer, Lumma and MetaStealer. It identified three conditions that let the attackers in: no multi-factor authentication, credentials that had never been rotated, and no network allow-lists.
Nothing published so far establishes that the same weaknesses apply at Asos, and the retailer has described the incident only as unauthorised activity on third-party platforms. Jonathan Lee of Trend Micro told Cyber Magazine the attack may point to “a wider compromise than the attackers claim,” because sending push notifications typically requires access beyond a cloud data platform. Marie Wilcox of Binalyze called the message “psychological warfare, designed to whip up panic,” and Tom Exelby of Red Helix advised revoking and rotating every credential and API key tied to the notification platform and Snowflake.
Markets and the phishing aftermath
Investors reacted fast. Asos shares fell as much as 13% on Tuesday, Quartz reported, and other outlets put the drop between roughly 10% and 14%. Quartz also noted that the delivery through Asos’s own app lent the message an apparent authenticity, and that the alert warned of unauthorised access to the company’s data infrastructure. Cyber Magazine reported that both the app and the website were still operating when it published, so the disruption so far has been to confidence and to the share price rather than to trading.
For customers, the practical exposure is names and contact details, which are the raw material for convincing phishing messages that cite the breach. The UK National Cyber Security Centre’s phishing guidance describes how attackers use researched details to make deceptive emails and texts look credible, and recommends filtering, reporting cultures and multi-factor authentication as layered defenses.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Common allergy, bladder and sleep pills tied to sharply higher dementia odds
- The second-largest U.S. reservoir just fell to its lowest level ever recorded
- Security experts still urge phone owners to switch off one location-tracking setting
- The FBI warns a new phishing trick can hijack your account without your password