ASOS App Push Alert Claims “ASOS HACKED”

The Record · Medium sophistication
Last updated October 7, 2026

ASOS customers reported receiving an alarming push notification in the ASOS app claiming the company’s Snowflake environment was “fully compromised” and threatening data leakage unless the company engaged. The message linked to a Telegram channel allegedly run by an extortion group, but the group provided no proof of access or stolen data.

What Happened

ASOS customers reported receiving a push notification through the company's own app, titled "ASOS HACKED." The message claimed that ASOS's Snowflake cloud data environment had been fully compromised and threatened to leak the data unless the company engaged with the senders. The notification linked to a Telegram channel calling itself Xuanye Group. Notably, the group provided no evidence that it had actually compromised ASOS's Snowflake environment, and later claimed payment information was not affected, again without proof.

Why This Pretext Works

This incident is notable because the alarm did not arrive via email or a spoofed website. It arrived through a channel customers already trust: the official ASOS app. Using an existing, legitimate communication channel lends the threat an air of authenticity that a typical phishing email lacks. The urgent, threatening language, "engage with us, or we will leak it," is designed to push recipients, including IT and data protection staff, toward a fast, panicked response rather than a measured verification process.

Red Flags to Watch For

  • An app notification claiming a hack and issuing a threat is an unusual channel for genuine incident communications.
  • Pressure language demanding immediate engagement to prevent a leak.
  • A redirect to Telegram rather than any official support or security channel.
  • Absence of concrete evidence, such as sample data or technical proof, despite claims of a full compromise.

Building Organizational Resistance

Security, IT, and communications teams should prepare for scenarios where attackers abuse a company's own legitimate customer-notification systems to create panic. Key steps include:

  • Treating alarming breach or ransom messages delivered through unusual channels, including push alerts or social media messages, as unverified until confirmed through official incident response processes.
  • Avoiding any instruction to engage with attackers through unapproved messaging platforms like Telegram, and instead routing such reports to internal incident response teams.
  • Establishing a clear, pre-planned communication protocol so customer support, PR, investor relations, and data protection staff know how to respond consistently if a similar alert appears, without amplifying unverified claims.
  • Reviewing access controls around customer-messaging and notification systems, since any confirmed abuse of such a system would indicate attacker access to at least part of that infrastructure.

Because the sole evidence for any breach was the appearance of the message itself as an app notification, organizations should resist drawing conclusions about the extent of compromise until verified technical evidence is available.

Key findings

  • Customers received an ASOS app push notification titled “ASOS HACKED” with an extortion-style message.
  • The notification linked to a Telegram channel calling itself “Xuanye Group.”
  • The alleged attackers provided no evidence they actually compromised ASOS or its Snowflake environment.
  • If the notification was truly sent via ASOS infrastructure, it suggests access to at least part of ASOS’s customer-messaging system.
  • The Telegram channel later claimed “payment information is not affected,” but provided no proof.

Who’s being targeted

  • Commonly targeted roles: Corporate Communications/PR, Investor Relations, IT, Security/Incident Response, Privacy/Data Protection (DPO), Customer Support.
  • Affected industries: Retail, E-commerce.
  • Attack channels: website, telegram.
  • Impersonated: Extortion group using ASOS branding/channel access (appearing as an official ASOS app notification).

Red flags to watch for

  • An app notification claims a hack and issues a threat (unusual channel for incident comms).
  • Pressure tactic: “Engage with us, or we will leak it.”
  • Redirect to Telegram (non-official support channel).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What did the ASOS push notification say?

The notification was titled "ASOS HACKED" and claimed the company's Snowflake environment was fully compromised, threatening a data leak unless ASOS engaged with the attackers.

Did the attackers prove they breached ASOS?

No. The group behind the message, calling itself Xuanye Group, provided no evidence that it had actually compromised ASOS's Snowflake cloud environment.

Why is this incident considered unusual?

If the notification truly came through ASOS's own app infrastructure, it would mean the attackers had access to at least part of the company's customer-messaging system, turning a legitimate channel into an extortion tool.

What should employees do if they see a similar alarming message?

Treat alarming breach or ransom messages delivered through unusual channels like app push alerts or social DMs as potentially fake until verified through official incident response channels, and avoid following links to unapproved platforms like Telegram.

Read the video transcript

Imagine this: you’re scrolling, and the official ASOS app pops up a push alert screaming, “ASOS HACKED.” The message says, “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” and it points you to a Telegram channel called “Xuanye Group.” Here’s the twist: they showed zero proof they’d actually hit ASOS or Snowflake. This is brand-channel abuse, turning a real customer notification system into a ransom note to scare you into clicking Telegram. If you ever see a breach or ransom alert pushing you to Telegram or any unapproved app, don’t tap it, screenshot it and send it to our security team through our official incident channel.

Categories

Similar attacks

ASOS App Push Alert Claims ‘Snowflake’ Breach

ASOS App Push Alert Claims ‘Snowflake’ Breach

ASOS customers received an unexpected push notification inside the official ASOS app claiming the retailer had been hacked and demanding engagement to prevent data leaks. ASOS confirmed it was an “unauthorised customer notification” tied to third‑party messaging platforms and said it restricted…

October 6, 2026
Fake “Asos hacked” alert pushes users to Telegram

Fake “Asos hacked” alert pushes users to Telegram

Asos customers received a mobile app notification claiming the retailer was “fully compromised” and warning of a Snowflake data breach. The alert included a link that redirected users to a Telegram channel allegedly run by a new cyber gang (“Xuanye”), suggesting a social-engineering attempt…

October 6, 2026
Fake Dubai Airports Recruiters Push Dev Malware

Fake Dubai Airports Recruiters Push Dev Malware

Researchers reported an Iranian state-aligned actor impersonating the Dubai Airports IT department to lure a targeted Iraqi individual into installing a fake “careers portal” and then opening a weaponized coding test. The workflow looked like a real recruitment process (HR questions, then a…

October 6, 2026
Fake Cops Threaten Arrest to Force Payments

Fake Cops Threaten Arrest to Force Payments

The FBI warns about phone scams where callers impersonate police or federal agents and threaten arrest unless the victim pays immediately. The scams use pressure tactics (keeping victims on the phone, urging secrecy) and push hard-to-trace payments like prepaid cards, crypto, wire transfers, or…

September 21, 2026
FBI: Fake Cops Swindle $1.6B via Threat Calls

FBI: Fake Cops Swindle $1.6B via Threat Calls

The FBI says scammers posing as law enforcement or government officials stole over $1.6B since January 2025, mainly by calling victims and threatening arrest, fines, or legal trouble unless they pay. Variants include jury-duty threats, targeted calls to medical professionals about license issues,…

September 18, 2026
Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026