Breaches · 5h ago
ASOS and the UK NCSC are investigating a cyber incident after some customers received an unauthorized “ASOS HACKED” push notification on Tuesday that claimed a Snowflake compromise. ASOS says names and contact details may have been accessed, while it does not believe payment card data or account passwords were affected.
The message appears to have come through ASOS’s own app, which made the threat look like an official company notice instead of an outside ransom note. That matters because the notification itself became the attack: it could speak with ASOS’s authority to every user who saw it, whether or not the backend theft claim is verified.
For retailers that use mobile apps to reach customers, the customer-messaging path is now part of the incident surface. If that channel is hijacked, it can trigger immediate panic, reputational damage, and market reaction even before investigators settle what, if anything, was taken from the underlying systems.
4 sources covering this story
ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.
Incident affecting ASOS customers
ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
Asos app delivers a data leak threat instead of fast fashion
Rogue notification claims Snowflake instance compromised, but customer info theft remains unverified
The Record from Recorded Future
Shares in British clothing company ASOS dive after hackers apparently send push notification
Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.
Part of the PlainSec briefing for 2026-10-06