INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ASOS Hackers Hijack App Notifications Claiming Snowflake Data Breach
| 2026-10-06 21:56 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On October 6, 2026, British online fashion retailer ASOS received a threatening notification from hackers claiming to have compromised the Snowflake instance and demanding engagement or data leakage. The attackers used ASOS's official mobile app to send notifications directly to customers, warning of impersonation and providing instructions on how to access their legitimate broadcast channel. The hackers claimed that customer information held on ASOS's server was safe but may have included names and contact details accessed by the attackers; however, payment-card information or account passwords were not impacted. ASOS restricted access to affected notification platforms, began working with cybersecurity specialists and relevant authorities, and acknowledged receiving an unauthorized push notification from customers.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
retailretail
Incident Timeline
October 6, 2026
Threat actors, claiming to be the Xuanye Group, hijacked app notifications on customers' phones and posted a link to their Telegram channel.
Click on any entity below to view its context and source!
industry
Retail
General Document Context
organisation
National Cyber Security Centre
Assisting ASOS
The UK’s National Cyber Security Centre is providing assistance to ASOS.
organisation
Screenshots
Screenshots shared by multiple recipients showed the same message:
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance.
organisation
Snowflake
Screenshots shared by multiple recipients showed the same message:
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance.
organisation
Telegram
The notification included a link to a Telegram channel operated by a previously unknown hacking group calling itself Xuanye Group.
organisation
Xuanye Group
The notification included a link to a Telegram channel operated by a previously unknown hacking group calling itself Xuanye Group.
organisation
Hackread.com
Hackread.com reviewed both channels.
organisation
Xuanye Group’s
Posts from Xuanye Group’s claimed official Telegram channel said payment information was not affected, the ASOS app remained safe to use and customer information was being held on the group’s server for a “designated period.”
organisation
Reuters
In a
statement
reported by Reuters, ASOS said it was investigating unauthorised activity involving third-party platforms used to communicate with customers.
organisation
AT&T
In 2024, attackers accessed data belonging to at least 165 Snowflake customers, including AT&T, Ticketmaster and Santander.
organisation
Ticketmaster and Santander
In 2024, attackers accessed data belonging to at least 165 Snowflake customers, including AT&T, Ticketmaster and Santander.
victims
165 Snowflake customers
In 2024, attackers accessed data belonging to at least 165 Snowflake customers, including AT&T, Ticketmaster and Santander.
organisation
ASOS
ASOS shares fell by about 10% after the incident became public, having dropped by more than 14% during trading.
Tactical Metrics
Metrics
victims
165
Snowflake Customers
Click for context!
In 2024, attackers accessed data belonging to at least 165 Snowflake customers, including AT&T, Ticketmaster and Santander.
Intelligence Sources
HackRead
2026-10-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:06
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
National Cyber Security Centre
entity
3x
tactic
Cyber Operation Type
Data Breach
tactic
2x
target region
Target Country
United States
country
2x
timeline
Temporal Reference
October 6, 2026
date
2x
general metric
%
10
%
Contextual Telemetry
Context Block
2 METRICS
industry
Targeted Sector
Retail
sector
victims
Snowflake Customers
165
snowflake customers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.