Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Apache Struts Flaws Allow Remote Code Execution
October 6, 2026
ASOS Hacked: App Users Receive Malicious Notifications
October 6, 2026
SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring
October 6, 2026
Home/CyberSecurity News/ASOS Hacked: App Users Receive Malicious Notifications
CyberSecurity News

ASOS Hacked: App Users Receive Malicious Notifications

Key Takeaways ASOS is investigating a cybersecurity incident following unauthorized notifications sent to app users. The notifications claimed a compromise of ASOS’s Snowflake data environment,...

Sarah simpson
Sarah simpson
October 6, 2026 4 Min Read
2 0

Key Takeaways

  • ASOS is investigating a cybersecurity incident following unauthorized notifications sent to app users.
  • The notifications claimed a compromise of ASOS’s Snowflake data environment, though this remains unverified by the retailer.
  • ASOS confirmed unauthorized activity on third-party customer communication platforms, potentially exposing basic personal information.
  • The company believes payment card information and account passwords were not impacted in this specific incident.
  • Customers are advised to avoid suspicious links and monitor for unofficial communications.

ASOS Investigates Cyber Incident After Malicious App Notifications

Online fashion retailer ASOS has launched an investigation into a cyber incident after numerous customers received rogue notifications via its mobile application. These messages, appearing on October 6, 2026, falsely asserted that hackers had successfully breached the company’s Snowflake data infrastructure. While ASOS has confirmed unauthorized activity involving external communication platforms, the claim of a Snowflake compromise has not been substantiated.

Table Of Content

  • Key Takeaways
  • ASOS Investigates Cyber Incident After Malicious App Notifications
  • ASOS Confirms Unauthorized Notification Activity
  • Previous Incidents and Market Reaction
  • What You Should Do

The alarming notification, prominently titled “ASOS HACKED,” surfaced around 10 AM BST. It directly addressed ASOS’s Data Protection Officer and IT department, leveraging a customer-facing channel to issue a public threat. The message stated, “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” and included a Telegram link, ostensibly for communication with the perpetrators. Although screenshots confirm the message’s delivery to customers, they do not provide evidence of the claimed database breach.

ASOS Hack Notification

ASOS Confirms Unauthorized Notification Activity

ASOS publicly acknowledged the incident, stating, “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.” The retailer confirmed that an “unauthorised customer notification” was sent and that it promptly restricted access to the affected notification systems. The company is actively collaborating with cybersecurity specialists and relevant regulatory bodies.

Initial assessments by ASOS indicate that basic personal information, such as names and contact details, may have been exposed. However, the company emphasized, “We do not believe that payment-card information or account passwords, were impacted.” This remains a preliminary assessment, with the full scope of the incident still under investigation.

Despite the disruption, ASOS confirmed that its website and mobile application continue to operate normally. The retailer also noted that it holds cybersecurity and business continuity insurance with a major global provider, though it is too early to quantify any potential financial impact on trading.

Snowflake is a widely utilized cloud data platform that businesses leverage for data storage and analytics. Cybersecurity experts highlight that a compromise of a notification platform does not automatically imply unauthorized access to critical cloud databases, payment systems, or the broader corporate network. Charlotte Wilson of Check Point, speaking to the BBC, suggested that the attackers’ primary motivation might be to publicly embarrass ASOS and force engagement, reiterating that the alleged Snowflake access remains unverified. Investigators’ immediate priorities include identifying the initial point of entry, determining all affected systems, and ascertaining whether any customer records were exfiltrated.

Previous Incidents and Market Reaction

This incident follows a separate report on August 25, 2026, detailing that ASOS customer accounts were accessed using compromised login credentials obtained from sources external to the company. That earlier breach, detected on July 28 and confirmed the following day, was attributed to credential stuffing attacks. The information potentially accessed in that instance included names, addresses, phone numbers, dates of birth, and limited payment card details, such as the last four digits and expiration dates. In response, ASOS blocked affected accounts and mandated password resets on July 29, also blocking or canceling suspicious transactions. ASOS states there is no confirmed link between the credential stuffing incident and the current investigation into the notification platform compromise.

Following news of the unauthorized notifications, ASOS shares experienced a significant decline, falling over 11% and reportedly seeing an intraday drop of up to 13%. The public nature of the notification brought the incident to light before its full implications could be thoroughly assessed.

What You Should Do

  • Avoid Suspicious Links: Do not click on the Telegram link or any other unsolicited links received in connection with this incident.
  • Monitor Official Communications: Rely solely on official updates from ASOS regarding the incident.
  • Watch for Phishing Attempts: Be vigilant for unexpected emails or text messages that might attempt to exploit this incident by requesting personal information, passwords, or payments. ASOS will not ask for your password via email or text.
  • Review Account Activity: Regularly check your ASOS account for any unusual activity.
  • Update Passwords: If you have reused your ASOS password on other online services, change those passwords immediately to unique, strong passwords.
  • Understand the Scope: Receiving the notification does not mean your phone has been hacked, but rather that a communication platform used by ASOS was compromised.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitHackerSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

SOC and MSSP Leaders Build Intelligence-Led Threat Monitoring

Next Post

Critical Apache Struts Flaws Allow Remote Code Execution

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Iranian Hackers Target Iraqi Critical Infrastructure With Fake Dubai Airports Coding Test
October 6, 2026
Ransomware Hacker Uses AI Coding Assistant to Attack Enterprise Networks
October 6, 2026
Critical Dell SupportAssist CVE-2024-28956 Vulnerability Allows Code Execution
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us