The news
ASOS (ASC), the British online fashion retailer, confirmed a breach of customer data after hackers used its app to send customers an unauthorized push notification on October 6. The company said basic personal information, including names and contact details, may have been accessed, according to Bleeping Computer.
The alert, which read in part "ASOS HACKED," was addressed to the company's data protection officer and IT team. It claimed the attackers had fully compromised the company's Snowflake instance, a cloud data platform, and threatened to leak the data unless ASOS engaged with them, Bleeping Computer reported. Mediaweek reported that customers in the UK and Australia received the message.
In a filing with the London Stock Exchange, ASOS disclosed that third-party platforms it uses for customer communications had been accessed without authorization, TechCrunch reported. ASOS said payment card data and account passwords were not compromised, and it did not confirm the claim that its Snowflake environment was breached, according to Bleeping Computer. TechCrunch reported that the exposed data includes home addresses, phone numbers, email addresses and customer profile notes such as website search queries.
How the attackers got in is not fully clear. TechCrunch, citing Bleeping Computer, reported that the attackers obtained Snowflake credentials by impersonating a trusted contact to obtain login credentials. A group calling itself Xuanye Group claimed responsibility but has provided no evidence of how much data it took or how many customers were affected.
ASOS said it took immediate action to restrict access to its notification platforms and was working with internal and external specialist advisers and the relevant authorities, Mediaweek reported. The company, which has about 17 million customers, said it holds cybersecurity insurance and that it was too early to quantify any impact on trading. Mediaweek reported that ASOS shares fell about 14% after the disclosure and closed down 9.56%.
The numbers
- ASOS customers
- About 17 million
- Share move after disclosure (per Mediaweek)
- Fell about 14%, closed down 9.56%
- Rogue alert sent
- October 6, 2026
Why CEOs should care
For CISOs, the striking detail is not the data but the delivery channel. Customer messaging tools, such as push notification and marketing platforms, can reach millions of phones in seconds, yet they are often managed by marketing teams with weaker controls than core systems. Ask who holds admin access to every platform that can message customers, whether multifactor authentication is enforced, and whether a single login can send a message to the whole customer base.
The reported method, impersonating a trusted contact to obtain credentials, is a help-desk and supplier problem as much as a technical one. Security leaders should review how staff verify requests for credentials or access, especially requests that appear to come from colleagues or vendors. Cloud data platforms such as Snowflake should require strong authentication on every account, including service and contractor logins.
For CFOs and boards, the market reaction is a reminder that a public-facing incident can move a share price before the scope is known. Mediaweek reported a drop of about 14% before shares closed down 9.56%. Boards should confirm that incident communications, regulatory notification and insurance claims are rehearsed, and that the company could say quickly and accurately what was and was not affected.
The bigger picture
Attacks on third-party data and communication platforms have become a common route into large consumer brands, because one compromised login can expose data held outside a company's own network. TechCrunch noted a similar 2026 breach at Betterment involving a third-party platform.
What’s next
ASOS has not said how many customers were affected. Watch for updates from the company, any action by the UK data protection regulator, and whether Xuanye Group publishes data. ASOS customers should be wary of messages that reference their orders or contact details.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








