Thursday, October 8, 2026
Tech Beat
Oct 8, 2026, 3:01 PMCybersecurity

Asos Data Breach Exposes Customer Details as Hackers Hijack App Alerts

Asos confirms hackers stole customer contact data from a third-party Snowflake platform, then used its app to threaten a leak; key access questions remain.

Listen to this briefingAudio briefing

Summary

On October 8, 2026, Asos confirmed in a London Stock Exchange filing that hackers breached a third-party platform hosting data used for customer communications. Stolen information includes names, home addresses, phone numbers, email addresses and customer-profile notes such as website searches. Xuanye Group then sent an unauthorized Asos app notification to the retailer’s data protection officer and IT department, claiming it had fully compromised Snowflake-hosted data and threatening publication unless Asos engaged. Many customers shared the message on social media.

The attackers reportedly impersonated a trusted contact to obtain login credentials. Snowflake said its systems were not breached, while it remains unclear whether Asos protected its Snowflake instance with multi-factor authentication or how the hackers accessed its push-notification system, which may involve another third party. Xuanye Group has not disclosed how much data it holds; Asos says it has 17 million customers. Earlier in 2026, hackers compromised Betterment through a third-party marketing platform, sent customers a cryptocurrency scam and accessed names, email addresses, phone numbers and other data.

Positives

  • Asos confirmed the breach in a London Stock Exchange filing and identified the compromised environment as a third-party customer communications platform.
  • Asos disclosed that names and contact information were stolen, providing an initial account of the exposed data.
  • Snowflake said its own systems were not breached, indicating the intrusion was confined to the customer-controlled environment.

Risks & concerns

  • Stolen records include home addresses, phone numbers, email addresses and profile notes containing website search queries.
  • Xuanye Group hijacked Asos app notifications to pressure the retailer into engaging or face publication of the stolen data.
  • Attackers reportedly impersonated a trusted contact to obtain login credentials for the Snowflake instance.
  • Asos has not established whether multi-factor authentication protected its Snowflake environment or how hackers accessed app notifications.
  • Xuanye Group has not quantified the stolen data, leaving the potential exposure across Asos’s 17 million customers unclear.
  • Betterment suffered a similar third-party platform compromise earlier in 2026, highlighting recurring risks in outsourced customer communications tools.
Primary sourceTechCrunchhttps://techcrunch.com/2026/10/08/asos-confirms-breach-of-customer-data-after-hackers-send-rogue-app-notification/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityOct 6

OpenAI Agents Target Wikipedia Tools and Flood Wikimedia With Traffic

CybersecurityOct 5

MCP Trust Flaws Let AI Agents Turn Prompts Into Internal Attacks

CybersecurityOct 5

Anthropic Expands Claude Cyber Access With Three Tier CVP