ASOS confirms data breach after hackers hijack app notifications
UK online fashion retailer ASOS confirmed that attackers used stolen employee credentials to access customer data via third-party platforms, after shoppers received hacker-controlled push notifications through its app.
- Victim
- ASOS
On 6 October 2026, customers of ASOS — the London-based online fashion retailer that ships clothing, footwear and beauty products worldwide — received alarming push notifications through the company's mobile app claiming their personal data had been stolen. The messages, which reached shoppers at around 10am, were sent by attackers who had gained access to one of ASOS's customer-messaging channels, and the retailer's shares fell more than 10% on the London Stock Exchange the same day.
ASOS later confirmed that the incident began with social engineering: an unauthorized party impersonated a trusted contact to trick an employee into handing over login credentials, then used that account to reach information held on certain third-party platforms the company relies on. A previously unknown group calling itself Xuanye Group claimed responsibility and urged ASOS staff to contact it on Telegram; researchers noted the group's channels had been created only the day the notifications went out.
What was accessed
ASOS said that full names, contact details and certain non-personal account information may have been accessed, but that payment card information and account passwords were not. The group's broader claims — including an assertion that it had compromised ASOS's Snowflake cloud environment — remain unverified: Snowflake said it found no evidence its platform had been breached, and researchers cautioned that the ability to send app notifications demonstrates access to a messaging channel rather than possession of a customer database. ASOS has not disclosed how many customers were affected.
Response
ASOS locked down the affected platforms and launched an investigation with external experts, law enforcement and regulators, and the UK's National Cyber Security Centre said it was in contact with the company and had offered support. The retailer told customers to ignore the unexpected alert and not click its link, and reiterated that it will never ask for passwords, security codes or payment details through unsolicited messages. ASOS said it has added further security measures and that its website and app remain safe to use.
Timeline
ASOS customers receive hacker-controlled push notifications through the retailer's app claiming their data was stolen.
ASOS confirms the breach began with social engineering and stolen employee credentials used to reach third-party platforms.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/
- fashionunited.comhttps://fashionunited.com/news/business/asos-confirms-cyber-attack-what-to-know/2026100775072