LONDON, Oct 8 — Asos, the UK online fashion retailer, has confirmed that hackers stole customers' personal information, after the attackers used the company's own app to broadcast a message announcing the breach to users.
In a filing with the London Stock Exchange, Asos said the hackers had gained access to a third-party platform that hosts data the company uses to communicate with customers. The company said names and contact details had been taken.
The incident became public in unusual fashion. Asos app users received what the company described as an "unauthorised customer notification", which many shared on social media. The message, addressed to Asos's data protection officer and IT department, claimed the hackers had "fully compromised" Asos data hosted on Snowflake, a data analytics platform used by corporate customers, and ended with a blunt demand: "Engage with us, or we will leak it."
Key facts at a glance
• Company: Asos, UK online fashion retailer with 17 million customers (per its website)
• Disclosure: filing with the London Stock Exchange
• Data confirmed by Asos: names and contact information
• Additional data reported by BBC News: home addresses, phone numbers, email addresses, notes on customer profiles such as search queries
• Platform involved: third-party Snowflake instance used for customer communications; Snowflake says its own systems were not breached
• Method reported by Bleeping Computer: impersonating a trusted contact to obtain login credentials
• Threat actor: Xuanye Group
• Extortion message: "Engage with us, or we will leak it."

What data was taken
Asos said the stolen information includes customer names and contact information. BBC News reported that the data also includes home addresses, phone numbers, email addresses and notes on customer profiles, such as search queries made on the Asos website.
The hackers have not disclosed how much data they hold. Asos has 17 million customers, according to its website, although it is not yet clear how many were affected.
Even without payment information, the data is valuable to criminals. Names, addresses, phone numbers and email addresses can be used in phishing campaigns, in which attackers impersonate trusted brands to trick people into revealing passwords or financial details. Information about shopping behaviour can make such scams more convincing.
How the attackers got in
According to Bleeping Computer, the hackers accessed Asos's Snowflake instance by "impersonating a trusted contact to obtain log in credentials" — a form of social engineering in which attackers deceive employees or partners into handing over access.
Snowflake said it had not suffered a breach of its own systems. The incident instead appears to stem from stolen credentials used to access Asos's account on the platform. It is not clear whether that account was protected by multi-factor authentication, a security measure that requires a second form of verification beyond a password.
It is also unknown how the attackers gained control of the app's push notification system, which is often run through a separate third-party service.
A new extortion tactic
The group behind the attack calls itself Xuanye Group. Its decision to use Asos's own notification system to publicise the breach represents an aggressive form of pressure. Rather than contacting the company privately, the attackers announced the compromise directly to customers, maximising reputational damage and increasing pressure on Asos to negotiate.



