- ASOS confirmed that third-party platforms it uses to message customers were accessed without authorisation, and that names and contact details may have been exposed.
- The attackers used the company's own notification channel to reach customers. This shows how much trust a vendor-run messaging tool can carry.
- Leaders should list every outside platform that can message customers in their name, and rehearse how to cut access and warn customers.
The attacker used the company's own voice
On the morning of Tuesday, October 6, a push notification appeared on ASOS customers' phones. It came through the retailer's own app, the channel customers expect to carry the retailer's own messages. The sender was not ASOS.
A company's customer messaging channel is part of its security perimeter, even when someone else runs it. Anyone who gains control of that channel can speak in the brand's voice.
Scale is what makes this matter. ASOS says it has 16.5m active customers in over 100 markets. BleepingComputer said the alert reached many, if not all, app users. The audience for a single message can therefore be large.
What ASOS has said
ASOS confirmed that an unauthorised notification went to its customers at around 10am UK time. It is investigating unauthorised activity on third-party platforms it uses to communicate with customers.
The company said it moved at once to limit access to those notification platforms. It is working with specialist advisers, inside and outside the firm, and with the relevant authorities.
On data, ASOS said names and contact details may have been reached. It does not believe card details or account passwords were affected. It added that its website and app continue to run normally.
On money, ASOS said it has a cyber insurance policy that includes business continuity cover. It called it too early to size any effect on trading.
What the attackers claim, and what is unproven
BleepingComputer reported that the notification read "ASOS HACKED". It was addressed to the company's data protection officer and IT team. It claimed a full compromise of the company's Snowflake instance. Snowflake is a cloud data platform.
The message pointed to a Telegram channel run by a group calling itself the "Xuanye group". BleepingComputer said the group later claimed it had stolen customer information.
ASOS has not confirmed the Snowflake claim. It has not said how many customers are affected. BleepingComputer said the group offered no evidence of the Snowflake compromise. It also did not say what data it holds or how many people are involved.
Those gaps matter. Confirmed facts and attacker claims are different things, and readers should keep them apart.
How a message like this reaches a phone
A push notification is a short alert that an app delivers to a phone's lock screen. Many companies send them through an outside messaging platform linked to the app. ASOS says it uses third-party platforms to communicate with customers.
That design is convenient. It also means that someone who gains access to such a platform may be able to message app users in the company's name.
The sources do not say how the attackers got into ASOS's platforms. They do show the effect. Many customers reported the same alert on Reddit. BleepingComputer said this indicates the message reached many, if not all, app users.
ASOS is now showing an in-app notice. It tells customers to disregard the alert and not to click the external link it contained.
Who carries the cost
Customers carry the first cost. They received an unexpected message from an app they trust, then had to be told to ignore it. Once a company asks people to doubt its own channel, it must work to restore their confidence in it.
Security and communications teams carry the second cost. They must warn people without sending a second message that looks like the first.
Questions to put to your team
First: which outside platforms can send messages, emails or alerts in our name? Ask for a complete list, including tools that marketing teams adopted on their own.
Second: who has access to each one, and what customer data sits inside it? ASOS says names and contact details may have been reached.
Third: how fast can we cut off a messaging platform? ASOS says it restricted access to its notification platforms immediately. Test whether your team can do the same.
Fourth: do we have a pre-agreed way to tell customers a message was not ours, through a channel the attacker does not control?
The lesson is plain. The channel you use to reach customers is also a channel an attacker can use to reach them. Give it the same scrutiny you give your payment systems.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: ASOS.





