Asos confirms data breach after fake app alert

Hackers used Asos’s own app to send an unauthorized warning after accessing a third-party platform. The stolen data includes names and contact details.
Asos has confirmed that customer personal data was stolen in a breach, after hackers used the retailer’s own app to send an unauthorized notification about the incident. That detail made the attack especially striking: the warning appeared through an official channel, but it did not come from the company. For customers, that meant a breach was accompanied by immediate confusion over whether a message from Asos could be trusted.
The company said the attackers accessed a third-party platform used to communicate with customers. As IT-PUB News reports, the information disclosed so far shows that names and contact details were taken, while other reports say home addresses, phone numbers, email addresses and some profile notes were also exposed.
Hackers used Asos’s own notification system
What sets this case apart is not just the data breach itself, but how the attackers tried to pressure the company.
Asos said the hackers sent an “unauthorised customer notification” through its app, and many users shared screenshots of it on social media. The message was addressed to Asos’s data protection officer and IT department and claimed the company’s data hosted on Snowflake had been “fully compromised.” It also warned: “Engage with us, or we will leak it.”
The tactic appears designed to force Asos into contact by turning the retailer’s own communication channel against it. For customers, the effect was straightforward: a breach alert seemed to come from an official app, even though Asos said it was not authorized.
What data was exposed
Asos said the breach involved customers’ personal information. In its filing with the London Stock Exchange, the company said names and contact information were taken.
BBC News reported that the stolen data also includes home addresses, phone numbers and email addresses, along with notes linked to customer profiles, such as website search queries.
The company has not said how much data the hackers claim to have or how many customers were affected. That leaves a major gap. Asos says it has 17 million customers, but the information released so far does not show whether the breach affected all of them or a smaller group.
Snowflake was involved, but not breached itself
According to Bleeping Computer, the attackers got into Asos’s Snowflake instance by impersonating a trusted contact to obtain login credentials. Snowflake said it had not suffered a breach of its own systems.
That distinction matters. Based on the details released so far, the incident appears to involve access to an Asos-related setup hosted on Snowflake, rather than a compromise of Snowflake’s core platform.
It is still unclear whether the Asos Snowflake instance was protected with multi-factor authentication. It is also not known how the hackers gained access to Asos’s system for sending in-app push notifications, which is often run through a third-party service.
The breach shows how customer tools can be turned against a brand
The Asos case shows how an attack can go beyond data theft. If attackers can reach a company’s customer-facing tools, they may also be able to send messages that look official and put extra pressure on the business.
That creates practical risks on both sides. For companies, the damage can include lost trust, disruption to customer communications and threats to publish stolen data. For customers, the immediate concern is exposure of personal details — and the possibility that messages appearing to come from a trusted brand may not be genuine.
The incident also follows a similar case earlier this year at fintech company Betterment, where hackers used access to a third-party marketing platform to impersonate the company and send a crypto scam to customers. In that breach, customer names, email addresses and phone numbers were also accessed.
Asos has not said how much data the Xuanye Group claims to hold, and the full scope of the incident remains unclear. Still, the breach has already drawn attention because it combines a familiar problem — stolen customer data — with a more unsettling tactic: using the company’s own app to announce the attack.