Skip to content
Cybersecurity

ASOS Confirms Customer Data Breach After Hackers Send Rogue App Notifications

ASOS logo illustrating the fashion retailer’s confirmed customer data breach and cybersecurity investigation.

British online fashion retailer ASOS has confirmed that some customer data was accessed during a cyberattack involving third-party platforms used by the company. The disclosure followed unauthorised push notifications sent through the ASOS mobile app on October 6, warning customers that the retailer had been hacked and threatening to leak information.

In a subsequent update, ASOS said an unauthorised individual had impersonated a trusted contact to obtain an employee’s login credentials. Those credentials were then used to access information on certain third-party platforms. The company restricted access to the affected systems and began investigating the incident with external specialists and relevant authorities.

What Customer Information Was Exposed?

ASOS said its initial investigation found that basic personal information, including customer names and contact details, may have been accessed. It also identified access to certain non-personal account-related information.

Reports have indicated that the exposed information may include email addresses, phone numbers, home addresses and customer profile details, such as website search queries. However, ASOS has not publicly established the full scope of the data involved or the number of customers affected.

The retailer said it did not believe payment-card information or account passwords had been compromised. It also confirmed that its website and app remained operational and safe to use.

How the Attack Unfolded

The incident became public after customers received a push notification titled “ASOS HACKED” through the retailer’s own app. The message claimed that the attackers had compromised an ASOS-associated Snowflake environment and threatened to release data unless the company engaged with them.

The notification directed recipients towards an external channel associated with a group calling itself Xuanye Group. The attackers’ claims about the extent of their access have not been independently established in full.

ASOS confirmed that the intrusion involved stolen employee credentials and third-party platforms, but the precise route through which the attackers sent the unauthorised app notifications remains unclear.

Why Third-Party Security Matters

The breach highlights the risks businesses face when employee accounts and external platforms connect different parts of their operations. Even if a company’s main website remains secure, compromised credentials can provide a route into systems used for customer communications or data management.

Organisations can reduce these risks through phishing-resistant authentication, strict access controls, monitoring of unusual account activity and regular reviews of third-party permissions. Incident response plans must also account for the possibility that attackers could misuse legitimate communication channels to reach customers.

ASOS has restricted access to the affected platforms and is working with specialists and authorities. The investigation will need to establish the full extent of the exposure and whether additional customer information was accessed.