Games
Games Finance Crypto Finance Fintech & Transfers Insurance Financial Reporting Banking Budgeting & Planning Auditing & KPIs Financial Planning Accounting Bookkeeping Cost Accounting Financial Statements Accounts Payable & Receivable Auditing Fixed Assets & Depreciation Accounting Software IFRS & GAAP Standards Marketing Brand Strategy Content Marketing SEO & AI Search Social Media Email Marketing Digital Ads TikTok Marketing & Shop Growth Hacking Marketing Analytics Pricing Psychology Brand Ambassadors Tools & Comparisons HR Compensation & Benefits Employee Engagement HR Strategy Recruitment & Talent Acquisition Sales B2B Sales AI in Sales CRM Systems Cold Outreach Pricing Strategy Pipeline Management Sales Enablement Sales Leadership Technology AI Tools & LLMs Cloud Infrastructure Cybersecurity Data Analytics Emerging Tech All β†’ Startup Corporate Governance Law Procurement Procurement: Sourcing Procurement: Vendor Management Procurement: Supply Chain Procurement: Contract Negotiation Procurement: Cost Reduction All Departments
Select Page
⚑ TL;DR
On Tuesday 6 October 2026, Asos customers received a rogue push notification headed “ASOS hacked” that pointed to a Telegram account and claimed the retailer’s Snowflake data environment had been compromised. Asos confirmed an unauthorised notification, said the incident involved third-party platforms it uses to communicate with customers, and said basic personal details may have been accessed while payment cards and passwords were not believed to be affected. If you received the alert, do not click the link, watch for phishing and treat your password hygiene as routine maintenance.

Most data breaches announce themselves quietly, through a regulatory filing or a note from a security researcher. The Asos incident was different: millions of shoppers had the news delivered directly to their phones by the attackers. A push notification from a trusted app, carrying an alarming message and a link, is a powerful and unusual tactic, and it offers lessons for every business that communicates with customers through apps, email or SMS.

What happened

According to reporting from BleepingComputer, ITV News and the BBC, customers began receiving a notification through the Asos app on the morning of 6 October. The message was headed “ASOS hacked” and read, in substance, as a message to the company’s data protection officer and IT team, claiming that its Snowflake instance had been fully compromised and demanding that the company engage with the attackers or face a leak. A Telegram link followed. The channel was reportedly linked to a group calling itself Xuanye Group.

Asos confirmed that an “unauthorised customer notification” had been sent. It said the activity involved third-party platforms it uses to communicate with customers, that it restricted access to the notification platforms immediately, and that it was working with specialist advisers and the authorities. It later emailed customers to apologise and to ask them to disregard the message and not engage with the link. An in-app notice now carries the same advice.

Timings differ between reports, which is common in the early hours of an incident, and some accounts mention alerts reaching phones earlier than the time Asos gave. Readers should treat precise timestamps as provisional until the company publishes a full account.

What data may be affected

Asos said that basic personal information, such as names and contact details, may have been accessed. It said it does not believe payment-card information or account passwords were affected. Importantly, the company has not confirmed the attackers’ specific claim about its Snowflake environment, and it has not said how many customers could be affected. Press reports quote figures of around 16.5 to 17 million customers globally for the retailer’s active customer base, but that is a description of the size of the customer base, not a confirmed count of affected people.

The UK’s National Cyber Security Centre has been in contact with Asos to offer support, and the company’s shares fell by more than 10% on the day of the news. Those two facts show the dual nature of an incident like this: it is both a security event and an immediate financial one.

Why a hacked push notification is such an effective attack

Security teams usually think about breaches as data leaving the building. This incident is a reminder that the communication channel itself is an asset. Marketing and engagement platforms typically hold API keys or admin credentials that can send messages to the entire user base. If an attacker obtains those credentials, they gain a megaphone with the company’s own authority.

That has several consequences:

  • Trust is borrowed. Users are trained to open notifications from apps they installed. A message that appears in the official app carries credibility that a random email does not.
  • Scale is immediate. One compromised credential can reach every opted-in device in minutes.
  • Extortion becomes public. Instead of a private ransom demand, the attacker uses customers as leverage by creating public pressure on the company.
  • Third parties widen the attack surface. The company said the incident involved third-party platforms, which is a reminder that your security is partly your vendors’ security.

What to do if you received the Asos alert

The advice from Asos and from the NCSC is consistent. For individual customers, here is a practical checklist:

  1. Do not click the Telegram link or engage with the senders. Their aim is attention and pressure.
  2. Delete or ignore the notification and read the official in-app notice or the email from Asos instead.
  3. Be alert to follow-up phishing. Criminals often exploit the news of a breach with fake “security update” emails or texts. Go to the Asos app or website directly rather than following links in messages.
  4. Change your password as a precaution, even though Asos does not believe passwords were affected, and do not reuse it on other sites. A password manager makes this painless.
  5. Turn on two-factor authentication where it is offered, for Asos and for your email account, which is the key to most other resets.
  6. Monitor your bank and card statements as a general habit. Asos says payment cards were not affected, but monitoring costs nothing.
  7. Watch for calls or messages that use your name and contact details, since basic personal information may have been accessed.
πŸ’‘ Pro Tip: Official updates will come through Asos’s own app, website and customer emails. If a message about the incident asks you to enter a password, confirm card details or call a number, treat it as a scam.

What retailers and other businesses should learn

The incident is a useful prompt for any business with a customer app. Consider the following questions in your next security review.

1. Who can send a message to all of your customers?

List every platform that can send push notifications, emails and SMS to your users, and who holds the credentials. Apply the same rigour you would to your payment systems: unique credentials, multi-factor authentication, role-based access and an audit trail.

2. Do you have send limits and approval workflows?

A mass message to an entire user base should not be possible with a single credential. Consider rate limits, approval steps for broadcasts above a threshold and alerts when unusual sends occur.

3. Can you cut off a channel quickly?

Asos said it restricted access to its notification platforms promptly. A rehearsed kill-switch, with named owners, shortens the window in which an attacker can use the channel.

4. How strong is your third-party risk management?

Ask vendors about their authentication controls, logging and incident notification terms. Make sure contracts require timely notice of any compromise, and review which of your vendors can touch customer data or customer communications.

5. Is your cloud data platform locked down?

The attackers referred to a Snowflake instance. Whether or not that claim proves accurate, cloud data warehouses have been a recurring target. Enforce multi-factor authentication, network policies, least-privilege roles and monitoring for unusual queries and exports.

6. Have you rehearsed communicating about an incident?

The quality of the first messages matters. Asos’s apology and its in-app notice told customers what to do, which is the right instinct. Prepare templates, decide who approves them and know your regulatory notification duties in advance.

Regulatory and reputational angles

In the UK, organisations that suffer a personal data breach likely to result in risk to individuals must notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high. Asos has not published the full detail of its notifications, and it would be inappropriate to assume what has or has not been filed. Whatever the regulator concludes, the commercial damage can be considerable: share price pressure, customer churn and the cost of forensic investigation, legal advice and customer support.

For a retailer that sells mainly to younger shoppers through an app, trust in that app is the business. The fastest way to rebuild it is to be transparent about what was and was not affected, to follow through on the promised updates, and to demonstrate concrete improvements rather than general assurances.

Questions customers are asking

Was my payment information stolen?

Asos says it does not believe payment-card information was affected. That is the company’s current assessment, and it may be updated as the investigation continues.

Do I need to delete the app?

There is no official instruction to do so. The unauthorised message came through the company’s communication tools, so the sensible steps are to ignore the alert, keep the app updated and follow Asos’s official guidance.

Should I turn off notifications?

You can, as a precaution, but it is not a substitute for caution. Treat any message that pressures you to click, pay or call as suspicious, whichever channel it uses.

Can I claim compensation?

That depends on whether you suffer a loss and on what the investigation finds. Keep a record of the messages you receive and any suspicious activity, and contact the company or the Information Commissioner’s Office if you have concerns about your data.

What we still do not know

  • Whether the Snowflake claim is accurate, and exactly what data was accessed.
  • How many customers are affected, as distinct from the size of the customer base.
  • How the attackers obtained access to the notification platform.
  • Whether any data will be leaked, and whether the attackers will follow up with further demands.

Asos has said it will provide further information as appropriate. Until then, the sensible stance for customers is calm vigilance rather than alarm.

Bottom line

The Asos incident is notable less for its technical sophistication than for its delivery method. By taking over a trusted communication channel, the attackers turned the company’s own app into a public-pressure tool. Customers should ignore the message, secure their accounts and watch for phishing. Businesses should treat messaging platforms and third-party tools as critical infrastructure, because in a world of connected apps, the channel you use to speak to your customers is also a channel an attacker can use.

This article is for general information and is based on public reporting available at the time of writing. Details of the incident may change as the investigation continues.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading