ASOS confirms breach after app alert claimed Snowflake access
Retailer says names and contact details may be exposed, not card data

ASOS confirms breach after app alert claimed Snowflake access

UK fashion retailer ASOS confirmed a data breach on 6 October 2026 after an unauthorized notification went out through its shopping app at about 10:00. The company has 16.5 million active customers in more than 100 markets. It has not said how many people received the alert or how many records were accessed.

What happened

ASOS told investors it is investigating unauthorized activity on third-party platforms used to message customers. It restricted access to those notification platforms and brought in internal and external advisers plus the relevant authorities.

A screenshot posted on Reddit shows the in-app message addressed to the ASOS data protection officer and IT team. It claimed the Snowflake instance was fully compromised and pointed readers to a Telegram channel run by a previously unknown group calling itself Xuanye Group. Reuters reported that the channel said payment information was not affected and that the app was safe to use. Snowflake told the BBC its investigation is ongoing and that it has so far found no compromise of its own platform.

ASOS said basic personal information, including names and contact details, may have been accessed. It does not believe payment-card data or account passwords were impacted.

Who is affected

  • ASOS customers who received the in-app message, and potentially a wider set whose names and contact details sat on the affected platforms.
  • Any retailer that lets a marketing or notification vendor push messages into a production app with standing credentials.
  • Not, on current statements, cardholder data or ASOS account passwords.

What to do now

Treat customer-messaging platforms as production admin access: inventory who can send, what else that token can reach, and how fast you can revoke it. If you run Snowflake or a similar warehouse for marketing, confirm the tenant is yours to lock down and that the vendor account is not the only control. ASOS customers should watch for phishing that uses their name and contact details. Do not treat an in-app message from an unknown group as the retailer speaking.

Source: Help Net Security, ASOS confirms data breach after hacked app alert reaches shoppers.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

.gh .sl .as registry hijacks minted 12 Google certificates
ccTLD DNS hijacks produced unauthorized TLS certs for Google domains