ASOS App Push Used to Send Hack Claim

Rapid7 Blog · Medium sophistication
Last updated October 8, 2026

ASOS customers received an unauthorized push notification sent through ASOS’s real mobile app. The message claimed ASOS’s Snowflake environment was compromised and urged recipients to contact the sender via Telegram, leveraging the trust people place in official app notifications. ASOS said it was investigating activity involving third-party customer-communication platforms and warned that names and contact details may have been accessed.

How the attack worked

Customers of ASOS received a push notification delivered through the retailer's own official mobile app, a channel they already trusted. The message claimed that ASOS's Snowflake environment had been compromised and directed recipients to engage with the sender through Telegram. ASOS later confirmed to media that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers.

The pretext relied on urgency and brand trust: a legitimate app notification telling customers to move the conversation to an unrelated chat platform to resolve a supposed security issue. This is a red flag pattern defenders should recognize, since legitimate support processes rarely ask customers to switch to apps like Telegram.

Why it succeeded

Most security awareness advice assumes there will be something suspicious for a recipient to notice, such as a spoofed sender address or an unfamiliar domain. Those checks become far less useful when the message arrives through the genuine app already sitting on someone's phone. Because the notification channel itself was authentic, customers had little reason to question its legitimacy before being redirected elsewhere.

This incident also illustrates a broader risk: a legitimate account, integration, or SaaS platform used in an unexpected way can provide access to attackers while generating activity that looks relatively ordinary when viewed on its own. ASOS said the activity involved third-party platforms used for customer communications, which can make misuse harder to distinguish from normal business operations.

What to watch for

  • A trusted brand notification that redirects you to an unrelated chat app to resolve a security issue
  • Urgent breach language without the normal in-app support steps
  • Requests to communicate outside official, known support channels
  • Follow-on messages referencing the original incident, such as fake refund offers, password reset prompts, or account security checks

Building resistance

Organizations and individuals can reduce exposure by treating the authenticity of a channel as separate from the legitimacy of its content. Even a message arriving through a verified app should be checked against official support pages or known contact methods before any action is taken, especially one that proposes moving the conversation elsewhere.

Teams managing third-party customer-communication tools should review permissions, integrations, and authentication controls regularly, since misuse of these platforms may not stand out from routine activity. Security awareness programs should also prepare stakeholders for a second wave of risk: once a real incident becomes public, a phishing email or text offering an account update, refund, password reset, or security check immediately has a credible event behind it, making it more convincing than typical phishing attempts.

Key findings

  • Attackers delivered an unauthorized push notification through ASOS’s own app, exploiting an already-trusted channel.
  • The push notification claimed a Snowflake compromise and directed recipients to engage via Telegram.
  • ASOS said it was investigating activity involving third-party customer-communication platforms.
  • ASOS warned that basic personal information (names and contact details) may have been accessed, but passwords and payment cards were not believed to be affected.
  • Snowflake stated it had not found evidence of a Snowflake platform compromise at the time.
  • The incident could enable follow-on scams (emails/texts) that reference the real event to appear more credible.

Who’s being targeted

  • Commonly targeted roles: Security awareness, Customer support / contact center, Marketing / CRM teams (owners of customer messaging platforms), IT / Identity & Access Management, Incident response / SOC.
  • Affected industries: Retail / e-commerce, Consumer mobile apps, Third-party customer communications / marketing platforms.
  • Attack channels: website, telegram.
  • Impersonated: ASOS (via the official ASOS app notification channel).

Red flags to watch for

  • A legitimate brand notification redirects you to an unrelated chat app (Telegram) to resolve a security issue
  • High-pressure breach language without normal in-app support steps
  • Unexpected request to communicate outside official support channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in the ASOS push notification incident?

ASOS customers received an unauthorized push notification through the company's own app claiming its Snowflake environment had been compromised and directing recipients to engage with the sender via Telegram.

Was ASOS customer data compromised?

ASOS said names and contact details may have been accessed, but passwords and payment cards were not believed to be affected, and it was investigating activity involving third-party customer-communication platforms.

Did Snowflake confirm a breach?

Snowflake stated it had not found evidence of a Snowflake platform compromise at the time.

Why is this incident concerning beyond the initial notification?

The incident could enable follow-on scams, such as emails or texts referencing the real event to appear more credible, including fake refund, password reset, or security check requests.

Read the video transcript

Imagine unlocking your phone and your ASOS app pops up: “Our Snowflake data was hacked. Message us on Telegram, now.” That actually happened. A hostile push went out through ASOS’s real app, abusing a trusted channel and telling customers to move the conversation to Telegram about a supposed Snowflake breach. Here’s the twist: Snowflake said they saw no compromise, and ASOS later confirmed it was an unauthorized notification via third-party messaging tools. The real danger is the second wave: emails or texts about refunds or password resets that name this exact incident to feel legit. If any app claims a breach and tells you to switch to Telegram, WhatsApp, or similar, stop. Close the message and go to the official website or in-app help yourself to check what’s real.

Categories

Similar attacks

ASOS App Push Alert Claims ‘Snowflake’ Breach

ASOS App Push Alert Claims ‘Snowflake’ Breach

ASOS customers received an unexpected push notification inside the official ASOS app claiming the retailer had been hacked and demanding engagement to prevent data leaks. ASOS confirmed it was an “unauthorised customer notification” tied to third‑party messaging platforms and said it restricted…

October 6, 2026
Fake “Asos hacked” alert pushes users to Telegram

Fake “Asos hacked” alert pushes users to Telegram

Asos customers received a mobile app notification claiming the retailer was “fully compromised” and warning of a Snowflake data breach. The alert included a link that redirected users to a Telegram channel allegedly run by a new cyber gang (“Xuanye”), suggesting a social-engineering attempt…

October 6, 2026
Handala Uses Fake “Support” Chats to Drop Malware

Handala Uses Fake “Support” Chats to Drop Malware

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer…

September 18, 2026
Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026