The ASOS Data Breach Sent the Scam Through the Brand's Own App

The ASOS Data Breach Sent the Scam Through the Brand’s Own App

A shopper in Leeds had three deliveries in transit on Tuesday morning. So when her phone buzzed with an alert from the ASOS app, she opened it without thinking. The title read ASOS HACKED. There was a link. She had approved that app’s notifications herself, years ago, and nothing had ever come through it except dispatch updates. That is the trap at the center of the ASOS data breach: the message arrived down a pipe she had already decided to trust.

Confirmation: confirmed by ASOS on October 6, 2026, which says third-party platforms used to communicate with customers were accessed without authorization. The attackers’ wider claim is not confirmed.

What happened in the ASOS data breach

At roughly 5:00 a.m. ET on October 6, 2026, ASOS customers received a push notification sent through the retailer’s own mobile app.

It was not from ASOS. The message read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It carried a link to a Telegram channel. A group calling itself Xuanye Group claimed responsibility.

ASOS then posted an in-app notice telling customers to disregard the alert and not to click or engage with the external third-party link it contained. The company confirmed unauthorized activity involving the platforms it uses to message customers.

So two separate things are on the table, and the ASOS data breach is easier to read if you keep them apart. One is confirmed: somebody got into a communication platform and used it to send millions of people a message. The other is a claim: that the attackers also hold a copy of the customer database from the company’s Snowflake environment. ASOS has not confirmed that, and the attackers have published no sample to back it up.

ASOS shares fell as much as 13 percent on Tuesday, which tells you how seriously the market read the second claim.

What the ASOS data breach exposed

ASOS has not disclosed a number. It has not said how many people received the notification, or how many records may have been reached.

What it did say is narrow and worth quoting exactly: “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.”

Read that in terms of what somebody can do with each piece.

  • Your name and email address. This is the raw material for a convincing fake. A scam
  • that opens with your real name, from a brand you really shop with, clears the first filter most people apply.

  • Your phone number, if it was in the contact details. Smishing is cheap, and a text
  • about a parcel is the easiest lie to tell someone who is expecting a parcel.

  • Your postal address. Less immediately useful to a scammer, but it is one more detail
  • that makes an impersonator sound like they are reading from a real file. Because they are.

Payment cards and passwords are, on ASOS’s own account, not in it. That matters, and it also narrows where the real risk sits.

Why a hijacked channel is worse than a leaked list

Most breach advice assumes the stolen data goes off to a forum and comes back weeks later as a clumsy email. This one skipped that step.

The attackers did not have to look credible. They borrowed a channel that was already credible. An app notification from a retailer you use is about as trusted as a message gets on a phone, because you opted into it, and because it has only ever carried real information before.

That is a lesson with a longer shelf life than this incident. The question worth asking of any message is not does this look real. It is did I choose to hear from this sender, and can anyone else send down that same route.

What to do now

Most of this has nothing to do with us, and it is the part that matters today.

Start with the next ten minutes.

  • Do not tap the link, and do not visit the Telegram channel. Nothing good is on the
  • other side of an extortion note’s link, including for the curious.

  • Expect the follow-up phish, dressed as ASOS. The next few weeks are when fake
  • “your order is on hold” and “confirm your account” messages arrive. Treat any message about an ASOS order as a prompt to open the app yourself and look, rather than a thing to tap.

  • Change your ASOS password anyway. ASOS says passwords were not impacted. Changing it
  • costs two minutes and removes the question.

Then spend twenty minutes on the things that outlast this breach.

  • If you reused that password anywhere, change it there too. That is the real exposure
  • in most retail breaches, and it is entirely in your hands. A password manager makes reuse stop being a habit.

  • Turn on the strongest sign-in each important account offers. For your email, your
  • bank and your main shopping accounts, take the app-based or passkey option over an SMS code where you are given the choice.

  • Watch the card you used, not for fraud alerts, but for small test charges. Card data
  • is reportedly not in this one. Checking is still free.

How OptMsg changes this exposure

OptMsg did not stop this, and it could not have. The breach happened inside another company’s systems, and the message that reached people came through a phone app rather than an inbox. We do nothing about a push notification. Say that plainly or the rest is not worth reading.

What an inbox changes is the second wave. Two mechanisms are worth naming at their real size. First, mail from a sender you have not approved goes to Trash instead of your Inbox, and it auto-deletes after 30 days. The message dressed up as an ASOS order confirmation lands there, in the pile you look through on purpose, rather than in the place you read on reflex. Second, an OptMsg account has no password, so a password leaked from another site cannot be tried on the inbox. Because email is the reset-and-recovery route into most of your other accounts, a door a stolen credential cannot open tends to keep the accounts behind it shut too.

Here is what that argument does not cover. It does nothing about a compromised device, a live phishing page you type your details into, or an attacker holding your unlocked phone. It does nothing about a notification from an app you installed, and it does nothing about a name and address already sitting in somebody’s copy of a database. What it narrows is the blast radius on your side. That is the whole claim.

If the question of how a message proves who sent it is the part that interests you, read how OptMsg thinks about sign-in and senders, or start an account and see what an inbox with a guest list feels like.

Create Your Account

Your Inbox. Your Rules.

Frequently asked questions

Was I affected by the ASOS data breach? ASOS has not published a number, so treat yourself as in scope if you have an ASOS account. The company says basic personal information including name and contact details may have been accessed.

Did ASOS lose my password or my card details? ASOS says it does not believe payment-card information or account passwords were impacted. Changing the password is still two minutes well spent, especially if you reused it.

Was the ASOS app itself hacked? What ASOS confirmed is unauthorized access to third-party platforms it uses to communicate with customers. That is how a message went out through the app without being sent by ASOS.

Did attackers really steal the customer database? That is their claim, not a confirmed fact. They said they compromised the company’s Snowflake environment, published no sample, and ASOS has not confirmed it.

What will the follow-up scam look like? An order problem, a refund, or a request to confirm your account, using your real name and arriving soon after the news. Open the ASOS app yourself and check rather than tapping anything in the message.

Sources

  • BleepingComputer, ASOS confirms data breach after “HACKED” in-app notifications, 2026-10-06 — https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
  • Hackread, ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach, 2026-10-06 — https://hackread.com/asos-hackers-hijack-app-notifications-snowflake-data-breach/
  • Quartz, ASOS stock drops 13% after hacker push notification, 2026-10-06 — https://qz.com/asos-stock-drops-hacker-push-notification-snowflake-100626
Scroll to Top