Someone Used Asos's Own App to Tell Shoppers It Had Been Hacked, and the Retailer Took Five Hours to Respond
An unknown group pushed a ransom note straight to Asos shoppers' phones through the retailer's own app. Whether any data was stolen is still unclear. Who controlled Asos's voice for a morning is not.

Around 10am UK time on Tuesday, Asos shoppers in the UK, Ireland and beyond picked up their phones to find a push notification from the fashion retailer's app titled "ASOS HACKED." The message wasn't meant for them. It was addressed to the company's data protection officer.
"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the notification read, followed by a link to a Telegram channel.
A group nobody had heard of
The channel was created that same day by a group calling itself the Xuanye Group, and held just three posts when the BBC checked. Sophos said no one had mentioned the group before on hacker forums or Telegram. The channel claimed "payment information is not affected" and made no specific demand.
Some experts noted the move mimics the style of extortion crews like ShinyHunters, whose antics include hijacking a rival gang's leak site. Talion's Natalie Page said it seems unlikely they were behind this one.
Five hours of silence
Asos said nothing publicly for more than five hours. In the meantime its website chatbot told customers the company was "aware of the notification and are currently investigating."
When the statement finally came, Asos confirmed that "at around 10am today, an unauthorised customer notification was sent to ASOS customers. We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers." It restricted access to those notification platforms and said it is working with specialists and authorities.
"Basic personal information including name and contact details may have been accessed," the retailer added. "We do not believe that payment-card information or account passwords, were impacted." Asos noted it carries cyber insurance and that "It is too early to quantify any potential impact on trading." The National Cyber Security Centre offered help.
Investors did not wait. Shares fell more than 10%, with some reports putting the intraday drop above 14%. Under UK law, Asos now has 72 hours to report the breach to the Information Commissioner's Office.
The Snowflake question
Whether the attackers actually got into a Snowflake database is unproven. It is not even clear Asos uses Snowflake directly. Malwarebytes points out that Asos's marketing stack uses Simon AI, which runs on Snowflake, alongside Braze to trigger push notifications. That is an indirect link, not evidence.
Dan Bird of Horizon3 told the BBC that "Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised."
The Snowflake name carries weight for a reason. In 2024, attackers used stolen credentials to raid hundreds of Snowflake customer accounts, including Ticketmaster, AT&T and Santander.
Losing the microphone
What is certain is that someone spoke to Asos customers in Asos's own voice. "The attackers didn't just steal from ASOS. They used ASOS's own voice to tell its customers about it. That's a complete loss of operational control," said Muhammad Yahya Patel of Huntress.
Cybernews researcher Aras Nazarovas argued that going public this way "greatly reduces the likelihood of the ransomware payment actually being made." Tenable's Gavin Millard warned of a longer tail: "If customer information has been exposed, criminals could turn it into convincing scams for months to come." Retail customer data is already a hot commodity, as the attacker who used rented AI agents to walk off with 600,000 stolen cards from online stores showed.
The hit lands on a company that was already struggling. Asos has 17 million active customers in more than 150 countries, down from 19.7 million. Its revenue fell to £2.5 billion in 2025 from £2.9 billion, with an operating loss of £212 million. Now it has to explain how a stranger got the keys to its loudspeaker.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free