Asos confirms breach of customer data after hackers send rogue app notification
Asos has confirmed a customer data breach after unknown attackers used the retailer's mobile app to send a push notification claiming the company's cloud storage had been 'fully compromised.' The company said hackers accessed a third-party platform used for customer communications and stole names and contact details, with media reports adding addresses, phone numbers, emails and profile notes may have been taken.
Why It Matters
The incident shows attackers are exploiting third-party platforms and in-app messaging to pressure firms and customers directly, highlighting risks in the supply chain and customer-communication channels for large retailers.
Key Facts
- Company: Asos
- Disclosure: Filing with the London Stock Exchange
- Claimed attacker handle: Xuanye Group
- Compromised platform (reported): Snowflake instance used by Asos (third-party cloud data platform)
- Data types reported stolen: Names and contact information; BBC reports include home addresses, phone numbers, email addresses, and profile notes (e.g., website search queries)
Asos has acknowledged a data breach after attackers used the retailer’s own mobile app to send customers a notification claiming the company’s cloud-hosted data had been compromised. The firm told the London Stock Exchange the intrusion targeted a third-party platform it relies on to communicate with customers, and that names and contact information were taken.
Media outlets report the stolen dataset may include home addresses, phone numbers, email addresses and notes attached to customer profiles such as website search queries. The unauthorised push message, which many recipients shared on social media, addressed Asos’ data protection officer and IT team and demanded engagement, warning the attackers would leak data otherwise. The message also named the cloud platform, stating the group had ‘fully compromised’ data hosted on Snowflake.
Security reporting indicates the attackers gained access to the Snowflake instance by impersonating a trusted contact to obtain credentials; Snowflake has said its own systems were not breached. It is not publicly known whether multi-factor authentication protected Asos’ Snowflake instance or how the attackers accessed the app’s notification system, which is commonly managed through a separate third-party service.
The group claiming responsibility uses the handle Xuanye Group and has not specified the amount of data it holds. Asos’ website lists about 17 million customers. The incident follows similar attacks earlier this year in which threat actors abused third-party marketing platforms to impersonate companies and harvest customer contact details.
Keep Reading

New York alleges TikTok gave teens, children a placebo safety feature instead of a real one

Goodfire says its new ‘inside-out’ monitors catch rogue AI agents at a fraction of the cost

OpenAI’s math solutions aren’t meeting the field’s standards yet
