INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ASOS Confirms Data Breach After Being Hacked in-App Notifications

| 2026-10-06 16:33 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On October 6, 2026, UK-based online fashion retailer ASOS confirmed a data breach after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. The attackers allegedly targeted third-party platforms used to communicate with customers without authorization and may have exposed basic personal information of multiple customers worldwide, including in the United States. The hackers directed ASOS to a Telegram channel operated by the "Xuanye group," which claimed that payment-card information or account passwords were not impacted but later published a statement claiming customer information was stolen during the attack; however, no evidence showing how many customers were affected or what specific data was compromised has been provided.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA retailretail
Incident Timeline
‎2026/10/06
Threat actors sent unauthorized push notifications through ASOS's mobile app, claiming to have stolen customer data from the company's Snowflake environment.
organisation ASOS
organisation Signal
organisation BleepingComputer
organisation Snowflake
organisation Telegram
organisation NFL
organisation CHANEL
Intelligence Sources
BleepingComputer 2026-10-06