Tuesday, 6 October 2026Live global desk
GlobalPulse
The world, tracked in motion
Business

ASOS app users receive notifications from hackers in apparent breach

ASOS app users in the UK received uninvited push notifications from hackers claiming a data breach and directing them to a Telegram channel.

Text:
⚡ GLOBAL PULSE BRIEF Business Focus
  • Headline Dispatch: ASOS app users receive notifications from hackers in apparent breach
  • Core Takeaway: ASOS app users in the UK received uninvited push notifications from hackers claiming a data breach and directing them to a Telegram channel.
  • Source Synthesis: Continuous live monitoring aggregated across major news wires and independent bureaus.
ASOS app users receive notifications from hackers in apparent breach
ASOS app users receive notifications from hackers in apparent breach

ASOS shoppers across the UK experienced unexpected disruptions when uninvited pop-up notifications appeared on their phone screens, indicating an apparent cyber security breach at the online clothing and beauty retailer.

Dozens of users turned to social media to express confusion and concern after receiving the alert. The notification read:

"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it"

Hackers, via ASOS app notification

Nature of the Breach and Industry Context

The unusual delivery method stunned security professionals. Most cyber criminal extortions and negotiations occur quietly behind closed doors, with attackers hoping discretion will prompt a private pay-off.

Charlotte Wilson, head of enterprise at cyber-security firm Check Point, described the incident to reporters:

"If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS's own app into their ransom note. Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company."

Charlotte Wilson, Head of enterprise at Check Point, via BBC

The notification specifically referenced Snowflake, a cloud platform utilized by various companies to collect, analyze, and store large quantities of data. Snowflake has previously been linked to high-profile data security incidents targeting other major services such as Santander and Ticketmaster. However, it remained unclear whether ASOS is an active customer of Snowflake or what specific data might be housed within such an instance.

Marijus Briedis, chief technology officer at software company NordVPN, noted that the attackers openly demanded engagement under threat of a data leak. Briedis explained that if the claim regarding Snowflake proves true, the critical question centers on what information was stored there and whether unauthorized access or downloading occurred. Briedis cautioned, however, that customers should not automatically assume personal or financial records had been compromised, as that has not been established.

The Telegram Connection and Hacker Profile

Cybersecurity analysts traced elements of the incident to the messaging platform Telegram. According to findings from security software company Sophos, users who clicked a link contained within the notification were directed to a channel named Xuanye gateway, which subsequently instructed them to join a second broadcast channel called Xuanye group.

In a post published to the channel, the group asserted that ASOS payment information remained unaffected. The group warned followers to beware of impersonation and directed formal inquiries to a specific Telegram account that charged a fee of ten Telegram stars per message.

Sophos monitors identified the Xuanye group as a newly emerged entity that had not previously appeared on dark web forums. Aiden Sinnot, principal threat researcher at the Sophos Counter Threat Unit, observed that new hacking collectives frequently wait for what they perceive as a significant opportunity to announce themselves in order to establish immediate credibility within the cyber-criminal ecosystem.

Market Impact and Expert Advice

MetricDetails
Market ImpactShares fell sharply following the notification
Attribution TargetASOS Data Protection Officer (DPO) and IT team
Linked Cloud PlatformSnowflake
Associated Telegram EntityXuanye group / Xuanye gateway

Security software providers and threat researchers strongly urged consumers who received the alert to avoid interacting with any included links. Experts warned that cyber criminals frequently exploit such apparent breaches by launching secondary phishing attacks, dispatching fraudulent emails or text messages masquerading as ASOS to trick users into resetting passwords or confirming payment credentials.

Asos did not immediately respond to the BBC's requests for comment.

📊 GLOBAL PULSE SENTIMENT

How significant is this development?

Participate in our community survey on the trajectory and real-world impact of this news.

Related stories