ASOS confirmed an unauthorized push notification was sent to customers through its official mobile app, claiming the retailer was “hacked” and threatening to leak data unless ASOS engaged with the attackers. The message attempted to pressure ASOS’ security and privacy teams and directed the company to a Telegram channel run by a group calling itself the “Xuanye Group.” ASOS said basic customer information may have been accessed, but it does not believe payment card data or passwords were impacted.
How the Attack Worked
On Oct. 6, ASOS customers received an unauthorized push notification through the retailer's official mobile app declaring the company had been hacked. The message, addressed to ASOS's data protection officer and IT team, claimed a fully compromised Snowflake instance and demanded engagement through a Telegram channel or threatened to leak data. The group behind the message identified itself as the Xuanye Group. ASOS said the notification was distributed through third-party platforms used to communicate with shoppers, and that it immediately restricted access to those platforms once the issue was identified.
Why It Succeeded
The notification arrived through a channel customers already trust, ASOS's own app. This is what made the message effective: recipients had no immediate reason to doubt its legitimacy because it came from a source they associate with routine order updates and promotions. The attackers used pressure and ultimatum language to force urgency, directing recipients toward a third-party Telegram channel to negotiate rather than asking them to click a traditional phishing link. Because the delivery mechanism itself was compromised, usual advice like checking the sender address or hovering over links would not have helped here.
What ASOS Confirmed
ASOS stated that basic personal information, including name and contact details, may have been accessed, but it does not believe payment card information or account passwords were impacted. The company advised customers to disregard the push alert and avoid opening any links it contained, directing them instead to verify directly through the official website or app.
What to Watch For
- Unexpected, alarming messages delivered through a marketing or notification channel rather than a typical support or security contact
- Pressure or ultimatum language demanding immediate engagement or response
- Instructions to move the conversation to an external platform like Telegram to negotiate
- Claims of a breach paired with a demand that bypasses official verification channels
Building Resistance
This incident illustrates why customer-facing notification and marketing platforms need to be treated as part of an organization's security boundary rather than purely as marketing tools. Teams managing these systems should apply the same access controls and monitoring as other customer-trust channels. For employees and customers alike, the core lesson is to treat unexpected security incident messages as potential scams, even when they appear to originate from a trusted brand, and to verify claims directly through official websites or apps instead of clicking links or engaging with unfamiliar contacts.
Follow-on phishing risk also rises after an event like this, since customers may now have difficulty distinguishing legitimate ASOS communications from attacker-controlled ones, making consistent verification habits more important going forward.
Key findings
- Attackers used ASOS’ official app notification channel to deliver an extortion message, leveraging customer trust in a legitimate communication channel.
- The push notification explicitly claimed a “fully compromised” Snowflake instance and attempted to force engagement via a Telegram channel.
- ASOS said the unauthorized notification was sent via “third-party platforms used to communicate with shoppers” and that it “immediately restricted access” to those platforms.
- ASOS stated that “basic personal information including name and contact details may have been accessed,” but it does not believe “payment-card information or account passwords were impacted.”
- The incident increases the risk of follow-on phishing because customers may have difficulty distinguishing legitimate ASOS messages from attacker-controlled ones.
Who’s being targeted
- Commonly targeted roles: IT, Security, Privacy / Data Protection, Marketing / CRM (customer communications), Customer Support.
- Affected industries: Retail (e-commerce), Consumer goods / fashion retail.
- Attack channels: smishing.
- Impersonated: ASOS (official mobile app notification channel).
Red flags to watch for
- Unexpected, alarming message sent to customers through a marketing/notification channel
- Pressure/ultimatum language demanding immediate engagement
- Routing the victim to a Telegram channel to negotiate
Frequently asked questions
What happened with the ASOS app notification?
ASOS confirmed an unauthorized push notification was sent through its official mobile app, declaring the retailer had been hacked and demanding engagement with attackers via a Telegram channel or risk having data leaked.
Was customer data exposed in the ASOS incident?
ASOS said basic personal information such as name and contact details may have been accessed, but it does not believe payment card information or account passwords were impacted.
How did attackers deliver the extortion message?
The message was distributed through third-party platforms ASOS uses to communicate with shoppers, which the company says it immediately restricted access to once the unauthorized notification was discovered.
What should customers do if they receive a suspicious ASOS message?
ASOS advised customers to disregard the push alert, avoid opening any links it contained, and verify any claims directly through the official ASOS website or app rather than clicking through.
Read the video transcript
Imagine this pops up on your phone from the real ASOS app: all caps, “ASOS HACKED.” That really happened. The message claimed ASOS’ Snowflake data was ‘fully compromised’ and told them: “Engage with us, or we will leak it,” then pointed to a Xuanye Group Telegram channel. Here’s the twist: attackers abused ASOS’ own third‑party messaging tools, so the alert looked totally legit. Your ‘trusted’ app, real logo, real name, fake emergency, pushing you to panic and follow their link. If you ever get a breach alert like that, from any brand: don’t tap the notification or its links, open the official app or website yourself and check there.