Tech5 MIN READ

Asos Confirms Customer Data Breach After Hackers Hijack App to Send Extortion Notification

The UK fashion retailer told the London Stock Exchange that hackers accessed a third-party platform holding customer data, after app users received a message demanding the company "engage with us, or we will leak it".

By Prathista Lazar · Author9 October 2026New
Asos Confirms Customer Data Breach After Hackers Hijack App to Send Extortion Notification

LONDON, Oct 8 — Asos, the UK online fashion retailer, has confirmed that hackers stole customers' personal information, after the attackers used the company's own app to broadcast a message announcing the breach to users.

In a filing with the London Stock Exchange, Asos said the hackers had gained access to a third-party platform that hosts data the company uses to communicate with customers. The company said names and contact details had been taken.

The incident became public in unusual fashion. Asos app users received what the company described as an "unauthorised customer notification", which many shared on social media. The message, addressed to Asos's data protection officer and IT department, claimed the hackers had "fully compromised" Asos data hosted on Snowflake, a data analytics platform used by corporate customers, and ended with a blunt demand: "Engage with us, or we will leak it."

Key facts at a glance

• Company: Asos, UK online fashion retailer with 17 million customers (per its website)

• Disclosure: filing with the London Stock Exchange

• Data confirmed by Asos: names and contact information

• Additional data reported by BBC News: home addresses, phone numbers, email addresses, notes on customer profiles such as search queries

• Platform involved: third-party Snowflake instance used for customer communications; Snowflake says its own systems were not breached

• Method reported by Bleeping Computer: impersonating a trusted contact to obtain login credentials

• Threat actor: Xuanye Group

• Extortion message: "Engage with us, or we will leak it."

4d4f80c8-a303-4be3-82a6-d666cd4d4160.png

What data was taken

Asos said the stolen information includes customer names and contact information. BBC News reported that the data also includes home addresses, phone numbers, email addresses and notes on customer profiles, such as search queries made on the Asos website.

The hackers have not disclosed how much data they hold. Asos has 17 million customers, according to its website, although it is not yet clear how many were affected.

Even without payment information, the data is valuable to criminals. Names, addresses, phone numbers and email addresses can be used in phishing campaigns, in which attackers impersonate trusted brands to trick people into revealing passwords or financial details. Information about shopping behaviour can make such scams more convincing.

How the attackers got in

According to Bleeping Computer, the hackers accessed Asos's Snowflake instance by "impersonating a trusted contact to obtain log in credentials" — a form of social engineering in which attackers deceive employees or partners into handing over access.

Snowflake said it had not suffered a breach of its own systems. The incident instead appears to stem from stolen credentials used to access Asos's account on the platform. It is not clear whether that account was protected by multi-factor authentication, a security measure that requires a second form of verification beyond a password.

It is also unknown how the attackers gained control of the app's push notification system, which is often run through a separate third-party service.

A new extortion tactic

The group behind the attack calls itself Xuanye Group. Its decision to use Asos's own notification system to publicise the breach represents an aggressive form of pressure. Rather than contacting the company privately, the attackers announced the compromise directly to customers, maximising reputational damage and increasing pressure on Asos to negotiate.

“Engage with us, or we will leak it.”
— Unauthorised notification sent to Asos app users

The tactic is not entirely new. Earlier this year, fintech company Betterment was compromised when hackers used access to a third-party marketing platform to impersonate the company and send a cryptocurrency scam to customers. In that case, the attackers also accessed customer names, email addresses and phone numbers.

Both cases highlight a growing vulnerability: the marketing, communications and analytics tools that companies use to engage customers often hold large volumes of personal data and can send messages that appear entirely legitimate. If attackers gain access, they can both steal data and abuse the company's trusted communication channels.

The third-party risk problem

Modern businesses rely on dozens or even hundreds of software providers for functions ranging from data storage to customer messaging. Each connection creates a potential entry point for attackers. Security teams must manage not only their own systems but the access credentials, configurations and vendors that link them to external platforms.

Cloud data platforms have become a particular focus. Because they store large, consolidated datasets, a single compromised account can expose vast amounts of information. Security experts have repeatedly urged companies to enforce multi-factor authentication, restrict access by network location and closely monitor unusual activity on such platforms.

Companies that have suffered similar incidents have often faced months of follow-up work: notifying customers, working with regulators, reviewing vendor security and, in some cases, dealing with legal claims. The cost of that remediation frequently exceeds the immediate cost of the incident itself.

The regulatory angle

Under UK data protection law, organisations must report qualifying personal data breaches to the Information Commissioner's Office, generally within 72 hours of becoming aware of them, and must inform affected individuals where the breach is likely to result in a high risk to their rights and freedoms. Regulators typically examine whether a company had appropriate technical and organisational measures in place — including access controls on third-party platforms.

What customers should do

Asos customers should be alert to emails, text messages and calls that claim to come from the company, particularly those asking for passwords, payment details or urgent action. Using unique passwords and enabling two-factor authentication where available can reduce risk. Customers who receive suspicious messages should contact the company through its official website or app rather than via links in messages.

The business impact

For Asos, the breach adds to the pressures facing a company that has been working to restore profitability in a highly competitive online fashion market. Data protection authorities in the UK and Europe may examine whether the company took adequate steps to secure customer information, and the incident could affect customer trust at a key time for retail trading.

For businesses worldwide — including India's fast-growing e-commerce and direct-to-consumer brands, which rely heavily on third-party marketing and analytics platforms — the case is a clear warning. Protecting customer data now means securing the entire chain of tools and partners that touch it, not just the company's own systems.

TagsAsosData BreachCybersecuritySnowflakeXuanye GroupExtortionPush NotificationSocial EngineeringRetailE-commerceLondon Stock ExchangeCustomer DataPrivacyThird-Party RiskMulti-Factor AuthenticationUK RetailFashionHackingBettermentData Protection

Reader reviews

Sign in to rate and review this article.
Loading reviews…