Morning Edition · №
Cybersecurity LONDON, ENGLAND

Asos Confirms Data Breach After Hackers Hijack Its Own App to Issue Threats

The British fashion retailer says attackers broke into a third-party platform holding customer contact data, then used Asos's own push notifications to warn: "Engage with us, or we will leak it."

SHARE X f in ⧉

Asos confirmed on Thursday that hackers accessed customer data after attackers used the retailer's own mobile app to send customers an alarming push notification — a message many recipients posted to social media. In a filing with the London Stock Exchange, the British fast-fashion company said an unauthorized party had broken into a third-party platform that hosts data Asos uses to communicate with customers, and that it was investigating an "unauthorised customer notification."

According to TechCrunch, the attackers gained access by impersonating a trusted contact to obtain login credentials for the account of an Asos employee, then used that access to reach the company's Snowflake-hosted data platform and its push-notification system. A group calling itself the Xuanye group claimed responsibility and addressed its message directly to Asos's data protection officer and IT department, warning: "Engage with us, or we will leak it." Snowflake said its own systems were not compromised, and it remains unclear how the attackers separately gained access to the notification system, which is typically run by a third-party vendor.

Asos has not disclosed how many of its roughly 17 million customers were affected. The company said names and contact information were exposed; other outlets have reported, citing BBC News, that the stolen data also includes home addresses, phone numbers, email addresses and notes on customer profiles such as past website search queries. Asos says no payment card numbers or account passwords were taken, and shares in the company fell nearly 10% in London trading after the breach became public, as investors weighed both reputational damage and the cost of the response.

The incident follows a similar pattern to a breach disclosed in January at fintech firm Betterment, in which hackers who had compromised a third-party marketing platform used it to blast customers with a fake cryptocurrency scam notification rather than quietly exfiltrating data. Security researchers say the tactic — hijacking a company's own trusted communication channel to pressure a target publicly — is becoming a more common extortion lever than the ransom notes attackers traditionally leave on compromised internal systems, precisely because it forces a public disclosure the company cannot control. Asos said it is continuing to investigate the scope of the breach, is working with external cybersecurity specialists and law enforcement, and has not said whether it will pay the attackers or notify affected customers individually.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →