Drooid Logo
Back to story perspectives

Full Breakdown

ASOS Push-Notification Hack Exposes Customer Data

By Drooid · · How we work

The Unauthorized Notification (Core Event)

On October 6, 2026 an unauthorised push notification appeared on ASOS mobile-app users’ home screens. Titled “ASOS HACKED,” it linked to a Telegram channel that identified the attackers as the “Xuanyewen” (also reported as the Xuanye Group). ASOS warned customers not to click the link and said no action was required on their accounts.

How Attackers Gained Access (Background & Context)

ASOS said the breach began when an unauthorised party impersonated a “trusted contact” to obtain login credentials for an employee account. Those credentials were then used to access third-party platforms that ASOS employs for customer communications, including a Snowflake-based environment and the Simon AI marketing tool.

The National Cyber Security Centre (NCSC) advised all ASOS customers to treat the incident as potentially affecting them, even if they did not receive the push notification.

Data Accessed and Potential Risks (Data & Statistics)

ASOS confirmed that the attackers may have obtained:

  • Names, delivery and email addresses, phone numbers, and customer numbers.
  • Recent search-history terms such as “reclaimed vintage,” “glamorous wide fit,” and “ASOS petite.”

Payment-card details and account passwords were not accessed. Analysts warned that the combination of personal identifiers and browsing behaviour creates a “starter pack” for highly personalised phishing attacks.

Official Statements & Responses

  • NCSC – Recommended customers remain vigilant for unexpected messages and to avoid sharing passwords or payment details via unsolicited contacts.
  • ASOS – Said affected platforms were “immediately locked down” and that the company is working with internal and external specialists, law-enforcement, and regulators.

Criticism & Consumer Guidance

Consumer-rights experts noted that compensation is not automatic; claimants must demonstrate actual harm. Nikki Stopford, co-founder of Consumer Voice, urged customers to keep any ASOS communications and records of any loss. Security advisers recommended changing passwords, enabling two-step verification, and treating any post-breach contact that asks for credentials as suspicious.

Conflicting Reports & Gaps

The primary discrepancy lies in whether the Snowflake environment was truly compromised. Snowflake’s investigation found no breach of its platform, while the attackers publicly claimed to have “fully compromised” the Snowflake instance and provided sample data to the BBC. ASOS has not disclosed how many customers received the notification or the exact volume of data copied, leaving the full scope uncertain.

Verbatim Quotes

  • “Much will depend on what happened to your data and the impact it has had on you.” — Nikki Stopford, Consumer Voice
  • “While passwords and payment information appear to be safe, the data that has been stolen will be incredibly valuable to scammers and used for many years to come,” — Jake Moore, ESET
  • “Getting a message like that from an app you trust is genuinely unsettling,” — Pete Membrey, ExpressVPN
  • “The apparent delivery of the message through ASOS’s own app makes this more concerning than an unsupported social-media claim,” — Pieter Arntz, malware intelligence researcher

Why It Matters

The incident triggered an immediate share-price drop of roughly 13 % on the London Stock Exchange and raised concerns about customer trust ahead of the holiday shopping season. Analysts warned that lingering doubts about data security could temporarily cap the pace of ASOS’s sales recovery. The push-notification attack highlights a growing risk: attackers exploiting trusted communication channels to amplify phishing campaigns. Ongoing vigilance and clear updates from ASOS will be essential to restore confidence among its 16.5 million global shoppers.