
Online fashion retailer ASOS is investigating a suspected cyberattack after thousands of customers received a brazen “ASOS HACKED” push notification through its official app claiming a full compromise of their data platform.
Hackers hijacked the official ASOS app to broadcast an extortion note reading, “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it: t.me/xuanyewengateway.”
A Data Protection Officer (DPO) is the corporate executive responsible for overseeing privacy compliance and ensuring a company safeguards its customers’ personal information.
Snowflake is a cloud platform used to store, process, and analyse vast datasets, including customers’ behavioural, transactional, and demographic information.
The rogue push notification included a link to the hackers’ newly created “Xuanye group gateway” Telegram channel, which was set up just hours before the broadcast.
The Daily Mail has contacted ASOS for official comment regarding the incident.
Despite the apparent breach, ASOS—which also owns Topshop and Miss Selfridge and serves 17 million customers across 150 countries—reported that its website and mobile app continue to function normally.
ASOS shares plummeted by 11 per cent following the emergence of reports detailing the apparent hacking incident.
Panicked customers have reacted online to the “crazy notification,” with some stating they have “never deleted my payment methods so quick” out of fear that their financial details might be stolen.
NordVPN Chief Technology Officer Marijus Briedis described the incident as featuring “an unusually brazen and threatening message.”
Marijus Briedis added that the attackers are not simply claiming a breach, but are publicly ordering the company to engage with them or risk having the obtained data leaked.
Marijus Briedis stated that if the hackers’ claims are genuine, the critical question will be what information was stored in that location and whether any of it was accessed or downloaded.
Marijus Briedis advised that at this stage, customers should not assume their personal or payment information has been stolen, as that has not yet been established.
Marijus Briedis warned that customers must be particularly alert to what happens next, as high-profile cyber incidents create the ideal conditions for phishing attacks.
Marijus Briedis explained that criminals may exploit publicity by sending deceptive emails or texts impersonating ASOS to request password resets, payment confirmations, order checks, or refund claims. You can read more about security precautions on the official ASOS platform.
Marijus Briedis added that the incident demonstrates the immense power of accessing a trusted communications channel, explaining that when an attacker can speak to customers directly through a company’s own systems, it makes the threat considerably more convincing and potentially much more damaging.
While the pervasive tracking capabilities of modern devices create highly detailed digital profiles, the prospect of utilising artificial intelligence for mass data surveillance and automated life interventions remains a deeply controversial topic.
While legal privacy frameworks like the UK GDPR strictly regulate how corporations use AI to track consumer information, technical device security relies on individual configurations such as disabling remote access, changing default passwords, and enforcing multi-factor authentication.
Apple HomeKit, Home Assistant, and privacy-focused hardware brands like Eufy, Aqara, and SwitchBot offer the best built-in privacy controls by prioritising local data processing and encrypted storage over vulnerable cloud networks.
ASOS has not yet released an official statement confirming what customer data, if any, has been exposed, though its online website chatbot has acknowledged that the company is actively investigating the notification.