Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-09 · tags: [incident, retail] · confidence: high · severity: high · affected_sectors: [retail] · au_impact: true

UK fashion retailer ASOS confirmed a data breach after attackers pushed an "ASOS HACKED" notification through its official mobile app at about 5 a.m. ET on 6 October, telling the ASOS DPO that they had "fully compromised the Snowflake instance." The company confirmed that third-party platforms used to communicate with customers were accessed without authorisation and that basic personal information, including names and contact details, may have been exposed; it said it does not believe payment-card details or account passwords were impacted, and it has not confirmed the threat actor's Snowflake claim or disclosed how many customers are affected. A group calling itself "Xuanye" claims to hold stolen customer information. The in-app notification is a novel and effective breach-notification vector, reaching customers before the company's own disclosure; the Snowflake compromise claim itself is not yet corroborated.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-10-07
Source BleepingComputer
Reliability Tier 2

Escalation — ASOS confirms its breach was caused by social engineering and credential theft (2026-10-09)

UK fashion retailer ASOS confirmed that a data breach was caused by a social-engineering attack in which hackers impersonated a trusted contact to obtain an employee's login credentials, then used those credentials to reach information on third-party platforms ASOS uses. The company locked down the affected platforms and opened an investigation with external experts, law enforcement and regulators. The disclosure follows the 6 October incident in which customers received rogue push notifications through the ASOS app claiming customer data had been stolen and urging staff to engage on Telegram; the actor, calling itself "Xuanye Group," claimed customer data but not payment information. ASOS has not published the number of customers affected. The case is a compact illustration of the current retail threat model — an employee-targeted social-engineering entry point, a third-party platform as the data store, and the victim's own app channel repurposed for the attacker's messaging.