ASOS customers reported receiving an alarming push notification in the ASOS app claiming the company’s Snowflake environment was “fully compromised” and threatening data leakage unless the company engaged. The message linked to a Telegram channel allegedly run by an extortion group, but the group provided no proof of access or stolen data.
What Happened
ASOS customers reported receiving a push notification through the company's own app, titled "ASOS HACKED." The message claimed that ASOS's Snowflake cloud data environment had been fully compromised and threatened to leak the data unless the company engaged with the senders. The notification linked to a Telegram channel calling itself Xuanye Group. Notably, the group provided no evidence that it had actually compromised ASOS's Snowflake environment, and later claimed payment information was not affected, again without proof.
Why This Pretext Works
This incident is notable because the alarm did not arrive via email or a spoofed website. It arrived through a channel customers already trust: the official ASOS app. Using an existing, legitimate communication channel lends the threat an air of authenticity that a typical phishing email lacks. The urgent, threatening language, "engage with us, or we will leak it," is designed to push recipients, including IT and data protection staff, toward a fast, panicked response rather than a measured verification process.
Red Flags to Watch For
- An app notification claiming a hack and issuing a threat is an unusual channel for genuine incident communications.
- Pressure language demanding immediate engagement to prevent a leak.
- A redirect to Telegram rather than any official support or security channel.
- Absence of concrete evidence, such as sample data or technical proof, despite claims of a full compromise.
Building Organizational Resistance
Security, IT, and communications teams should prepare for scenarios where attackers abuse a company's own legitimate customer-notification systems to create panic. Key steps include:
- Treating alarming breach or ransom messages delivered through unusual channels, including push alerts or social media messages, as unverified until confirmed through official incident response processes.
- Avoiding any instruction to engage with attackers through unapproved messaging platforms like Telegram, and instead routing such reports to internal incident response teams.
- Establishing a clear, pre-planned communication protocol so customer support, PR, investor relations, and data protection staff know how to respond consistently if a similar alert appears, without amplifying unverified claims.
- Reviewing access controls around customer-messaging and notification systems, since any confirmed abuse of such a system would indicate attacker access to at least part of that infrastructure.
Because the sole evidence for any breach was the appearance of the message itself as an app notification, organizations should resist drawing conclusions about the extent of compromise until verified technical evidence is available.
Key findings
- Customers received an ASOS app push notification titled “ASOS HACKED” with an extortion-style message.
- The notification linked to a Telegram channel calling itself “Xuanye Group.”
- The alleged attackers provided no evidence they actually compromised ASOS or its Snowflake environment.
- If the notification was truly sent via ASOS infrastructure, it suggests access to at least part of ASOS’s customer-messaging system.
- The Telegram channel later claimed “payment information is not affected,” but provided no proof.
Who’s being targeted
- Commonly targeted roles: Corporate Communications/PR, Investor Relations, IT, Security/Incident Response, Privacy/Data Protection (DPO), Customer Support.
- Affected industries: Retail, E-commerce.
- Attack channels: website, telegram.
- Impersonated: Extortion group using ASOS branding/channel access (appearing as an official ASOS app notification).
Red flags to watch for
- An app notification claims a hack and issues a threat (unusual channel for incident comms).
- Pressure tactic: “Engage with us, or we will leak it.”
- Redirect to Telegram (non-official support channel).
Frequently asked questions
What did the ASOS push notification say?
The notification was titled "ASOS HACKED" and claimed the company's Snowflake environment was fully compromised, threatening a data leak unless ASOS engaged with the attackers.
Did the attackers prove they breached ASOS?
No. The group behind the message, calling itself Xuanye Group, provided no evidence that it had actually compromised ASOS's Snowflake cloud environment.
Why is this incident considered unusual?
If the notification truly came through ASOS's own app infrastructure, it would mean the attackers had access to at least part of the company's customer-messaging system, turning a legitimate channel into an extortion tool.
What should employees do if they see a similar alarming message?
Treat alarming breach or ransom messages delivered through unusual channels like app push alerts or social DMs as potentially fake until verified through official incident response channels, and avoid following links to unapproved platforms like Telegram.
Read the video transcript
Imagine this: you’re scrolling, and the official ASOS app pops up a push alert screaming, “ASOS HACKED.” The message says, “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” and it points you to a Telegram channel called “Xuanye Group.” Here’s the twist: they showed zero proof they’d actually hit ASOS or Snowflake. This is brand-channel abuse, turning a real customer notification system into a ransom note to scare you into clicking Telegram. If you ever see a breach or ransom alert pushing you to Telegram or any unapproved app, don’t tap it, screenshot it and send it to our security team through our official incident channel.