Asos Confirms Customer Data Breach After Hackers Hijack App Notifications

Asos confirms a customer data breach after hackers hijacked app notifications via a third-party platform, exposing personal information, including names and contact details.

Oct 8, 2026 - 14:40
 2
Asos Confirms Customer Data Breach After Hackers Hijack App Notifications
Image Credit: TechAmerica.ai / AI-generated image

British online fashion retailer Asos has confirmed a customer data breach after hackers accessed a third-party platform and sent unauthorised notifications through its mobile app. The incident exposed names and contact details, although Asos says payment information and account passwords were not compromised.

The company disclosed the breach in a London Stock Exchange filing after customers received messages threatening to publish stolen data unless Asos responded.

Asos Confirms Customer Data Exposure

The compromised information included names and contact details held on customer communication platforms. BBC News reported that the records also contained home addresses, phone numbers, email addresses and customer profile notes, including website search queries.

ASOS has not disclosed how many customers were affected or how much data was stolen. The company maintains that the attackers did not access payment card information or passwords.

Hackers Obtained Credentials Through Social Engineering

According to BleepingComputer, the attackers impersonated a trusted contact to obtain login credentials used to access third-party systems. The group identifying itself as Xuanye Group claimed to have compromised Asos data hosted on Snowflake.

Snowflake said its infrastructure was not breached. It remains unclear whether the affected account had multi-factor authentication or how the attackers accessed Asos’ app notification system.

Hackers Used App Notifications to Threaten Data Leak

On October 6, customers received unauthorised push notifications addressed to Asos’ data protection and IT teams. The messages threatened to release stolen information unless the company engaged with the attackers.

Asos subsequently secured the affected platforms and began investigating with external cybersecurity specialists and relevant authorities. The company has also introduced additional security measures.

Asos Says Shopping Services Remain Safe

Asos says its website and app remain safe to use and has advised customers to be cautious of suspicious communications. The retailer serves millions of customers internationally, according to its corporate information, but its total customer base does not indicate how many people were affected.

The investigation is continuing, and ASOS has not released a final assessment of the breach’s scope.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav is a technology writer at TechAmerica.ai, covering artificial intelligence, startups, digital platforms, consumer technology, mobility, and emerging technologies. Her reporting follows major developments across the global technology industry, from AI companies and startup funding to product launches, regulatory investigations, software platforms, and changes affecting large technology markets. At TechAmerica.ai, Shivangi looks beyond the initial announcement to understand what a development means in practice. Her coverage often examines how new technologies, regulatory decisions, and business moves could affect companies, consumers, and the wider industry. She writes for an international audience, focusing on clear, well-researched reporting that gives readers useful context on fast-moving technology stories.