ASOS customers in the UK were alarmed on Tuesday (October 6, 2026) after receiving an unusual push notification from the fashion retailer’s mobile app that appeared to have been sent by hackers. The message, titled “ASOS HACKED”, claimed attackers had compromised a Snowflake instance and threatened to leak data unless the company engaged with them. Dozens of users reported receiving the alert.
ASOS has acknowledged receiving the notification and is investigating, but has not confirmed a cyberattack or data breach. The retailer’s website and app continued to operate, while the extent of any potential unauthorized access remained unclear.
The notification was addressed to ASOS’s data protection officer and IT team rather than customers. It claimed that the attackers had “fully compromised” the Snowflake instance and instructed the company to engage with them or face a data leak.
The message also directed recipients to a Telegram channel apparently associated with a group calling itself the Xuanye group. Cybersecurity researchers said the group was not previously known in major hacker forums, raising questions about whether the claims can be independently verified.
Snowflake is a cloud-based platform businesses use to store, process, and analyze large volumes of information. The alleged compromise has raised concerns since such systems can contain sensitive business and customer data.
However, no one has confirmed that ASOS customer information was accessed or stolen. Security experts said the fact that a message apparently reached users through ASOS’s own app could indicate access to systems connected to the retailer’s notification infrastructure, but it does not, by itself, establish how much data, if any, was compromised.
Also Read: Why AI Agents Need Cybersecurity Memory to Protect Enterprise Data
The incident also affected investor sentiment. ASOS shares fell by more than 10% in morning trading after reports of the alleged breach emerged. The company had previously seen its shares rise strongly during 2026.
Cybersecurity specialists are also warning customers to remain alert for follow-up phishing attempts. Criminals could potentially exploit the publicity around the incident by sending fake ASOS emails or messages asking users to reset passwords, confirm payment details or verify orders.