ASOS App Hack: Attackers Used Push Notifications to Send a Ransom Note

SafeDep Team
• • 4 min read

On October 6, 2026, people with the ASOS app got a push notification that said the company had been hacked. Attackers sent it. They had gotten into the third-party tools ASOS uses to message its customers, and they used that access to send an extortion note straight to people’s phones. ASOS has confirmed that names and contact details may have been accessed. The bigger claim, that the attackers “fully compromised” ASOS’s Snowflake data warehouse, is still unproven, and Snowflake says its platform was not breached.

Most breaches come out through a company statement or a leak site post. This one landed on customers’ lock screens first, before ASOS had said anything publicly.

What the notification said

The alert started showing up around 5:00 a.m. ET on Tuesday, October 6, according to BleepingComputer. Users in the UK and several other countries got it. The message read:

ASOS HACKED
Dear Asos DPO and IT, we have fully compromised the Snowflake instance.
Engage with us, or we will leak it.

It was signed “xuanyewengateway” and linked to a Telegram channel run by a group calling itself the Xuanye Group. Some versions went out in both English and Hebrew, and Israeli customers were among those who got it.

The note is addressed to ASOS’s Data Protection Officer and IT team, not to customers. Customers were just the delivery channel. Sending it this way makes sure the company cannot quietly ignore the demand, because thousands of people (and the press) see it at the same time.

What ASOS has confirmed

ASOS put out a statement later that day. The key points:

  • The company is investigating unauthorised activity involving the third-party platforms it uses to communicate with customers.
  • Basic personal information, including names and contact details, may have been accessed.
  • According to ASOS, payment card details and account passwords were not affected.
  • It locked down access to the notification tools and brought in outside experts and the authorities.
  • The website and app kept working normally.

ASOS has not said how many customers are affected, which third-party platforms were involved, or what data was actually taken. ASOS shares dropped more than 10% on Tuesday morning after the news spread.

The Snowflake claim

The attackers say they got into ASOS’s Snowflake instance. Snowflake says it has “found no compromise of the Snowflake platform.” Both can be true, since attackers can log into a single customer’s account with stolen credentials without Snowflake itself being hacked. That is how the 2024 UNC5537 campaign exposed around 165 Snowflake customers.

Infosecurity Magazine reported that ASOS uses Simon AI for marketing, which runs on Snowflake. That could link the notification tooling to the data warehouse, but nobody has confirmed it. So far, the push notifications only prove the attackers could reach the messaging system.

How the attackers probably got in

The initial access vector has not been publicly disclosed, so this section is based on common attack patterns rather than confirmed findings. Credential theft, phishing, or weak authentication are the likely ways in. In practice, sending a push notification to every app user usually needs one of these:

  • A login to the push or marketing platform’s dashboard, often from a phished or infostealer-stolen account without MFA.
  • An API key or service token for that platform, often found in code, CI logs, a leaked config file, or an old integration nobody rotated.

Either one gives the attacker a “send to all users” button. Push and marketing tools are built to reach the entire customer base with one click, so a single leaked key is a lot of power. These tools also tend to be connected to customer data sources to personalize messages, which is why the jump from “can send notifications” to “can read customer data” is believable even if it is not proven here.

The activity maps to these MITRE ATT&CK techniques:

TechniqueID
Valid AccountsT1078
Exploit Public-Facing ApplicationT1190
Account Manipulation: Additional Cloud RolesT1098.003
Application Layer Protocol: Web ProtocolsT1071.001
Exfiltration Over Web ServiceT1567
Data ManipulationT1565

What customers should do

If you got the notification, you do not need to panic, but a few things are worth doing:

  • Do not click the Telegram link or message the group.
  • Expect phishing. Attackers who have your name and email may send fake “ASOS refund” or “verify your account” emails. ASOS will not ask for your password over email.
  • Change your ASOS password if you reused it anywhere else, even though ASOS says passwords were not affected.
  • Turn on MFA anywhere it is offered.

Open questions

As of October 9, 2026, these are still unanswered:

  • Which third-party platform or platforms were accessed.
  • How the attackers got the credentials or keys.
  • Whether any data was actually taken from Snowflake or anywhere else.
  • How many customers are affected.

This post will be updated if ASOS, Snowflake, or researchers publish more details.

Sources

  • incident-response
  • cloud-security
  • extortion

Author

SafeDep Logo

SafeDep Team

safedep.io

Share

The Latest from SafeDep blogs

Follow for the latest updates and insights on open source security & engineering

Background
SafeDep Logo

Ship Code.

Not Malware.

Start free with open source tools on your machine. Scale to a unified platform for your organization.