ASOS app users got a push notification reading "ASOS HACKED", claiming its data store was fully compromised, linking to a Telegram channel. I run AliasFleet: an email-alias service where every account gets its own forwarding address, so a leak names its source. Hours later, ASOS confirmed it had been hacked. Most breaches are announced in a press release; this one was announced by the attacker, through the victim's own app, to the victims themselves. I have read enough breach disclosures to know what happens next: the notification channel is poisoned, and the phishing wave is about to start.
What ASOS has confirmed, and what it has not
Credit where it is due: ASOS moved fast on the confirmation. The company says it is investigating the unauthorised activity, has taken immediate action to restrict access, and has apologised to customers. The key line from its statement: "basic personal information including name and contact details may have been accessed". It added that it does not believe payment card information or account passwords were impacted.
Here is the honest split between what is confirmed and what is still murky:
| Confirmed | Still unconfirmed |
|---|---|
| The push notification was real and went to ASOS app users on Tuesday morning, October 6 | Whether customer data was actually exfiltrated, or only reached |
| ASOS confirmed it was hacked and is investigating | Whether email addresses specifically were among the "contact details" |
| "Basic personal information including name and contact details" may have been accessed | Whether the Snowflake instance was actually compromised; Snowflake says its platform shows no compromise |
| Payment cards and passwords are not believed to be impacted | How many customers are affected; no victim count given |
| ASOS told customers to disregard the notification and not click the link | Who is behind the "Xuanye" Telegram channel; researchers do not recognise the group |
The "may have been accessed" wording is the honest one. ASOS knows the intruder got somewhere, and it does not yet know what they took. The Times reports around 16.4 million active customers, which is the pool of people who should be paying attention while the investigation runs.
Tuesday morning, as it happened
The alert went out at around 10am. The text: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." It included a link to a Telegram channel called the Xuanye group gateway. The Sun reports that over 400 customers flagged the issue on Downdetector, and confused customers posted screenshots of the notification on X. ASOS shares fell more than 10 percent in the hours after the alert, according to The Times.
Sky News reporting, via The Times, adds a useful detail: ASOS uses a customer data platform called Simon AI that runs on Snowflake, pulling behavioural, transactional and demographic data into individual customer profiles. Sky News says details like customers' clothing sizes and measurements could be in those profiles. None of it is confirmed as accessed. What is confirmed is that the attacker could push a message through ASOS's own notification system, which means the hack is not limited to some read-only data warehouse. Alan Woodward, professor of cybersecurity at the University of Surrey, put it plainly: if the hackers can send a push notification, they have probably got access to the database, and "if I was an Asos customer, I would assume that somebody's got my personal data."
The Sun reports that a message posted in the Telegram channel reads "Regarding Asos, payment information is not affected." Do not take the attacker's word for anything. In this case ASOS agrees on that point, but the principle stands: the person extorting the company is not a source.
The notification channel is the story
Data breaches are common. What is rare is the delivery mechanism. The attacker did not post the data somewhere and wait for the press to notice; they used the retailer's own app to broadcast a ransom note to the retailer's own customers. That is public extortion in the most literal sense, and it does something no leaked spreadsheet can do: it breaks trust in every future message the brand sends.
Think about the week ahead from a customer's point of view. ASOS will inevitably email its customers about this incident. The attackers know those emails are coming. Charlotte Wilson, head of enterprise for the UK and Ireland at Check Point, told The Sun that customers should be "extremely suspicious of emails, texts or messages claiming their ASOS account has been compromised, offering refunds or asking them to reset passwords through a link". Go to the app or the site directly, she said, never through a link.
"The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS's connected systems, but it doesn't prove their full claims about the extent of the data breach." (Jake Moore, ESET global cybersecurity advisor, via The Sun)
Breach notifications are the scammers' favourite raw material. Every "ASOS breach" refund offer, password-reset email, or account-warning text you get in the next few weeks should be treated as hostile until proven otherwise. Real companies never ask for passwords or bank details in a message.
What to do if you shop at ASOS
- Do not touch the notification. Do not click the Telegram link, do not join the channel, do not reply. ASOS says to disregard it entirely.
- Go to the source yourself. If you want updates, open the ASOS app or type asos.com into your browser. Never follow a link in a message about this breach, even one that looks right.
- Assume breach emails are bait. Any email, text, or DM offering refunds, account recovery, or "verification" because of the hack is hostile until proven otherwise. This is the main attack vector for the next month.
- Change your password if you reused it. ESET's Jake Moore advises changing the app password and anywhere else the same one was used. Do it now rather than after the investigation concludes.
- Switch on two-factor authentication on your email and your banking. Your ASOS contact details are exactly the ingredients of most account-recovery flows.
- Watch your accounts. Check bank statements for unfamiliar transactions and keep an eye on your credit report.
- Check Have I Been Pwned once the incident is listed. It is the canonical record of which addresses have leaked and where.
The breach-response guide walks through all of this in order.
The address you gave ASOS is the receipt
Here is the part that matters for the long term. You cannot change your name. You cannot change your home address. Once "name and contact details" are in a stolen file, they stay there. But the email address you handed ASOS was a choice, and it is the one part of your identity you can make expendable.
In practical terms: if the address you gave ASOS had been an alias used only for ASOS, the email address in the stolen file is a fingerprint. Every phishing message that lands on it from now on is either from ASOS or from whoever took the file. Pause or delete that alias and the whole attack channel dies while your real inbox stays clean. That is the leak-tracing mechanism in practice: the address itself names the company that handed it to the attacker, and no investigation is required.
Retailers are the perfect use case for this, because they sit on exactly the data that makes phishing work: your name, your address, your order history, your sizes. What the attacker gets from a breach like this is not the data alone; it is the data plus your trust in the brand. An alias does not stop the breach. It stops the breach from following you. If you have not used one before, this explains what an email alias is, and the set-up guide takes about two minutes.
What to watch while the investigation runs
Three things to watch. First, the extent of the data access: ASOS says "may have been accessed", which is where every breach story starts, and the victim count and data classes will matter when they land. Second, whether the dataset surfaces publicly, which would turn a contained intrusion into a circulating one. Third, the copycat risk: a push-notification hijack that tanks a share price by 10 percent in a day is a technique other attackers are now studying. If it worked this visibly once, it will be tried again.
ASOS says no secondary misuse has been confirmed. That is a point-in-time finding. A file of names and contact details that could touch any of 16.4 million active customers does not get used on day one. It gets used in the weeks after, when the breach notifications arrive and the impersonators move in. Watch the channel you gave them. UniladTech's full account of the alert is worth a read if you want the blow-by-blow.
Top comments (0)