← ASOS

2026 ASOS — Xuanye Group push alerts; third-party messaging access; Snowflake claim unverified

2026 Unknown records affected Share on X

Data compromised

ASOS: names and contact details may have been exposed; payment cards and passwords not believed impacted. Actor claim: customer information stolen from alleged Snowflake instance (unverified count/fields)

Technical writeup

Verified ASOS confirmation (BleepingComputer / Guardian / DataBreaches, Oct 6, 2026): unauthorized activity involving third-party platforms used to communicate with customers; names and contact details may have been exposed; payment-card data and account passwords not believed impacted; company restricted notification-platform access and told customers to ignore the rogue push. Separately, Xuanye Group sent “ASOS HACKED” in-app push notifications (~5:00 a.m. ET) claiming full Snowflake compromise and threatened to leak customer data via Telegram — ASOS has not confirmed Snowflake access or published an affected-customer count (recordsAffected 0). companyConfirmed true for messaging-platform unauthorized access.

Root cause

Unauthorized access to third-party customer communication / push-notification platforms (ASOS confirmed); Xuanye Group also claimed Snowflake compromise (not company-confirmed)

References