
Customers of British online fashion retailer ASOS received a push notification through the company’s own app on Tuesday titled “ASOS HACKED.” The message read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It linked to a Telegram channel run by a group calling itself Xuanye Group, a name that experts who track cyber extortion groups had not seen before. ASOS shares fell more than 10% after the alert went out, and the company did not respond to The Record’s request for comment.
None of this is confirmed. The group provided no evidence that it breached ASOS’s Snowflake cloud data environment, and the Telegram channel contained no samples of customer data. A later post from the group said payment information was not affected, again without proof. The only evidence of a hack is the notification itself, which, if genuine, would mean whoever sent it had access to at least part of ASOS’s customer-messaging infrastructure. There is no public evidence that ASOS uses Snowflake to send push notifications, or that the alert came from its Snowflake environment. Extortion groups normally contact a company privately before going public, which makes this approach unusual.
How to check if you’re affected
Affected products and accounts are not yet known, because ASOS has not said what, if anything, was accessed. In the meantime, reasonable precautions for anyone with an ASOS account are:
- Do not tap the link in the “ASOS HACKED” notification or join the Telegram channel it points to.
- Change your ASOS password and any other account that shares it, and turn on two-factor authentication if the app or site offers it.
- Treat any email, text or call that references an ASOS “data leak” as suspect until ASOS publishes its own notice.
