Asos users report concerns after receiving push notification from cyber criminals

Asos users have told of their “shock and alarm” after receiving messages apparently sent by cyber criminals.

Users across the UK received a message on their smartphone this morning (6 October) warning of a data breach and urging the company to comply with demands.

Asos smartphone notification warning of a data breach, with alert message stating: "ASOS HACKED"

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message reads. The notification also warned the online retailer to “engage with us or we will leak it”.

In the wake of the notification, thousands of users took to social media to report their own experiences, contacting the retailer online for clarification. One user told they were shocked by the notification, but did not engage with the message or embedded link.

“It’s unusual for me to check the Asos notifications but this one caught my attention,” they said. “It’s very concerning and I’m worried about my information being leaked.”

“As someone who’s been a scam victim in the past I’m extra vigilant.”

Another told they were in a “state of shock and alarm” after receiving the message.

Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

“It’s rather concerning that I’ve received a message from what seems to be some form of hacker group while on my way to work,” they said.

At this stage, it appears that the notification isn’t primarily aimed at compromising customers, but instead used as a blackmail tactic to force the retailer to comply with demands.

Exact details on the scope of the breach, if any has occurred, are also yet to be revealed by the retailer. approached Asos for comment, but did not receive a response by time of publication.

Why was Snowflake mentioned in the Asos message?

Snowflake is a data management service provider used by enterprises globally. The company has been linked to a series of data breaches in recent years, including at companies such as Ticketmaster and AT&T.

Jake Moore, Global Cybersecurity Adviser at ESET, said the incident ranks among one of the most “visible” cybersecurity incidents in recent memory. Concerningly, the notification suggests the threat actor(s) may have gained deep access to Asos systems.

“This has got to be one of the most visible hacks in history,” he said. “The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of Asos’s connected systems, but it doesn’t prove their full claims about the extent of the breach.”

“By broadcasting their breach directly to ASOS app users, the threat actors are likely trying to apply pressure to ASOS, showing how extensive their access is so they can leverage some sort of ransom,” Moore added.

Dan Bird MBE, field CTO for Emea at Horizon3, echoed Moore’s comments regarding the scope of the breach.

“Sending a push notification to Asos’s app users would require access to the company’s notification system, which is separate to the Snowflake data platform the attackers claim to have compromised,” he commented.

“If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door.”

Who’s behind the Asos attack?

Details on who is behind the attack remain murky. However, the link sent to users directs them to a Telegram channel created today. This channel is believed to have been created by a group dubbed the ‘Xuanye Group’.

Moore urged users to avoid clicking on the notification or attempting to access the Telegram group.

FOLLOW US ON SOCIAL MEDIA

You can also .

Original source Asos users report concerns after receiving push notification from cyber criminals

Back to home