ASOS Hacked: Attackers Sent Their Threat Through the Store's Own App

What Happened in the ASOS Hack?
On October 6, 2026, users of British fashion retailer ASOS's app received a notification on their phones titled "ASOS HACKED", addressed to the company's data protection officer and IT team: "We have fully compromised the Snowflake instance. Engage with us, or we will leak it." It carried a link to a Telegram channel run by a group calling itself Xuanye Group. ASOS confirmed the notification was unauthorised and said basic personal information, including names and contact details, may have been accessed by an unauthorised party, but that it does not believe payment-card information or account passwords were affected. If you have an ASOS account, do not tap the link, change your password if you use it anywhere else, and treat any message claiming to be from ASOS over the coming days with suspicion.
What ASOS Has Confirmed, and What It Hasn't
The company's statement set out three points:
- The source: unauthorised activity involving third-party platforms ASOS uses to communicate with customers. The company immediately restricted access to its notification platforms and is working with specialist advisers and the relevant authorities.
- The data at risk: names and contact details, but not payment-card information or passwords, based on its current assessment.
- The service: the website and app are operating normally. ASOS apologised to customers by email and asked them to disregard the notification and not click the link.
What has not been disclosed: how many people received the notification, how many records may have been taken, and which platform was used to send it. Snowflake, a cloud platform for storing and analysing data, said its investigation found no compromise of its own platform. Security firm Sophos said the group had never been mentioned before on hacker forums or other Telegram channels. The UK's National Cyber Security Centre (NCSC) is assisting ASOS.
On the financial side, ASOS shares fell more than 14% during trading on the London Stock Exchange and closed down 9.56%. The company said it holds cyber insurance that includes business continuity cover, and that it is too early to quantify any impact on trading. Searches for "asos hacked" also appeared among trending searches in Saudi Arabia on Google Trends, so this affects users here too.
What to Do Now if You Have an ASOS Account
- Don't tap the notification link or contact the channel. This is ASOS's own advice.
- Change your password on ASOS and on any other site where you use the same one.
- Turn on two-step verification for your email and banking apps. The UK NCSC calls it one of the most effective ways to protect online accounts.
- Watch your bank statement for anything unusual.
- Expect phishing. A name, phone number and email are enough for a fraudster to write a convincing message about a "refund" or a "password reset". Go to ASOS through its website or app directly, never through a link you received in a message.
Receiving the notification does not mean your phone was hacked. It was sent from the company's systems, not from your device.
Lesson One for Stores: Your Notification Channel Reaches Every Customer
The most dangerous part of this incident is not the data alone. The attackers used the store's own notification platform to put their threat on every customer's screen, turning pressure on the company into a public crisis within hours. Security experts pointed out that sending a push notification to app users requires access to the notification system, which is separate from the data platform the attackers claim to have reached. That means your customer messaging platforms, from app notifications to SMS, email and WhatsApp, need the same protection as your database:
- Mandatory two-step verification on every account that can send, including agency and outside marketers' accounts.
- A separate "send to all customers" permission held by very few people, ideally requiring a second person's approval.
- API keys for these platforms kept in a secrets vault, not in code, rotated regularly, and revoked the moment an employee leaves or an agency contract ends.
- An instant alert on any bulk send outside the usual schedule.
Lesson Two: A Data Warehouse Can Fall to One Stolen Password
There are no confirmed details yet on how the attackers got into ASOS's systems. But there is a known precedent: in 2024 Mandiant tracked a campaign against Snowflake customer accounts, and Mandiant and Snowflake notified about 165 potentially exposed organisations. The cause was not a flaw in the platform. It was credentials stolen by infostealer malware from systems Snowflake did not own, some dating back to 2020, used on accounts without multi-factor authentication. The defences are not complicated:
- Two-step verification for every user on your data platform, and keys rather than passwords for system accounts.
- Access restricted to your company's known network addresses.
- Copy no more into your analytics warehouse than the analysis needs. Phone numbers and emails can be masked or replaced with tokens.
- Alerts on large exports and unusual queries.
Lesson Three: Write the Incident Plan Before the Incident
ASOS issued a statement the same day, apologised to customers by email, and disclosed its insurance position. That is not improvised on the day of a crisis. In Saudi Arabia, SDAIA's procedural guide on personal data breach incidents requires the controller to notify the competent authority within 72 hours of becoming aware of an incident that may harm the data or the people it belongs to, and to notify affected data subjects without delay if they are harmed. Prepare in advance: who decides, who speaks for the company, the text of the customer message, and how to shut down every sending channel within minutes. For the details, read our guide to the Personal Data Protection Law.
How We Build It at Origami
When we build a store or an app for our clients, we treat notification and messaging platforms as part of the attack surface, not a side marketing tool: tightly held send permissions, keys stored outside the code, a log of every send, and a single kill switch for all channels. If your store is already live, we start with a short review: who can message your customers today, where their data gets copied, and whether every account has two-step verification. Simple questions, but their answers are what separate an incident contained quietly from a notification landing on every customer's phone. Also read cybersecurity essentials for small and medium businesses.
Sources
- ASOS: Unauthorised ASOS Notification, customer care page (October 6, 2026)
- The Guardian: ASOS statement, share price and NCSC comment
- BBC: 'Asos hacked': What can I do to protect myself?
- Hackread: the notification and Xuanye Group's claims
- Mandiant: the 2024 campaign against Snowflake customer instances
- SDAIA: Personal Data Breach Incidents Procedural Guide
Frequently asked questions
Was my data leaked in the ASOS hack?+
That is not confirmed yet. ASOS said basic personal information, including names and contact details, may have been accessed by an unauthorised party, and that it does not believe payment-card information or passwords were affected. The company has not said how many customers are affected, so follow updates on its official website directly.
Is the ASOS app safe to use now?+
ASOS said its website and app are operating normally and that it restricted access to its notification platforms. Receiving the notification does not mean your phone was hacked, because it was sent from the company's systems. As a precaution, change your password and do not open any link you receive in ASOS's name.
I got the ASOS HACKED notification. What should I do?+
Do not tap the link or contact the channel. Change your ASOS password and any account that uses the same one, turn on two-step verification for your email and banking apps, watch your bank statement, and be wary of any message or call asking you to reset a password or offering a refund.
How do I protect my online store from a hack like ASOS's?+
Turn on two-step verification for every account on your data platform and your notification and messaging platforms, limit the send-to-all-customers permission to a few people with a second approval, keep keys in a secrets vault and rotate them, alert on bulk sends and large exports, and prepare an incident plan that covers notifying the competent authority within 72 hours.
Follow Origami in Google
Pin Origami as a preferred source and our articles will surface first for you in Google Search and Top Stories.

Related articles
- CybersecurityOffice 2021 and Windows Server 2012 R2 Get Their Last Security Patch on October 13. After That, NothingMicrosoft ends support for Office 2021, Windows Server 2012 R2 and Windows 11 24H2 on October 13, 2026. How to find them in your company and act before the deadline.
- CybersecurityApple Tightens Mac Full Disk Access. Which AI Agents Already Have It?Apple will require very explicit consent before a Mac app gets Full Disk Access, citing AI agents. How to check which apps on your company Macs already have it.
- CybersecurityPlant Controllers Left Open on the Internet: Attackers Broke Water Systems by Editing One Logic FileSince July 2026 attackers have exploited internet-exposed PLCs at water utilities in at least 12 US states, disabling alarms. What that means for your plant and Saudi OTCC controls.
- CybersecurityPatching Magento Alone Won't Save Your Store — Attackers Were In Three Days EarlierCVE-2026-75650 in Magento and Adobe Commerce scores a perfect 10 and was exploited three days before Adobe's patch. What is affected, how to check your store, and why updating is not enough.
- CybersecurityBlack Hat 2026 Enterprise Java Flaws: Why Your Internal System Is Not SafeBlack Hat 2026 research exposed 12 enterprise Java flaws, including pre-auth remote code execution in Bonita BPM and Apache OFBiz. What it means for your business systems.
- CybersecurityAI Just Found Cryptography Weaknesses Experts Missed: What It Means for Your BusinessAnthropic's AI found new weaknesses in HAWK post-quantum cryptography and AES. Nothing you use today is broken — here's what it means for your business.
Have a project in mind?
We build custom systems, apps and websites for your business. Tell us your idea and we will give you a straight answer on it.
