ASOS Confirms Cyberattack, Data Breach
Description
British online retailer ASOS confirmed a cyberattack involving the compromise of a third-party communication platform used to send notifications to users. Hackers sent rogue notifications to ASOS users' mobile apps, claiming full compromise of ASOS's Snowflake data platform instance and threatening data leaks. ASOS stated that basic user information such as names and contact details may have been accessed, but payment card information and passwords were not impacted. The company’s website and app operations remain unaffected. The incident was claimed by a hacking group named Xuanye Group, possibly a Chinese-speaking threat actor or a false flag. ASOS has restricted access to the compromised notification platform and is working with specialists and authorities. The exact initial access vector and details about the third-party platform remain undisclosed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ASOS experienced a cyberattack where hackers compromised a third-party communication platform used for customer notifications, resulting in unauthorized rogue notifications sent to users. The attackers claimed to have fully compromised ASOS's Snowflake instance, a data analysis platform, and threatened to leak data. ASOS confirmed potential exposure of basic user information but no impact on payment card data or passwords. The company’s core website and app were not affected, and operations continue normally. The attack was claimed by the Xuanye Group, with possible links to prior Snowflake breaches by other threat actors. ASOS has taken immediate action to restrict platform access and is collaborating with internal and external experts and authorities. Details about the compromised third-party platform and the exact attack vector remain undisclosed.
Potential Impact
Potential exposure of basic user information including names and contact details. No confirmed compromise of payment card information or account passwords. No disruption to ASOS website or application operations. The incident may cause reputational damage and user trust concerns. The rogue notifications sent to users could be used to increase pressure on ASOS via publicity and extortion tactics.
Defensive Guidance
ASOS has restricted access to the compromised third-party notification platform and is working with internal and external cybersecurity specialists and relevant authorities. Users should be informed about the incident and advised to remain vigilant for suspicious communications. Since the company’s website and app were not affected and payment information was not compromised, no immediate password or payment method changes are mandated. Monitor vendor advisories for updates on the third-party platform and Snowflake instance investigations. Patch status is not yet confirmed — check vendor advisories for current remediation guidance.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/asos-confirms-cyberattack-data-breach/","fetched":true,"fetchedAt":"2026-10-07T09:48:20.932Z","wordCount":1102}
Threat ID: 6ac615652cdf04f656344afb
Added to database: 10/07/2026, 09:48:22 UTC
Last enriched: 10/07/2026, 09:48:26 UTC
Last updated: 10/07/2026, 15:48:26 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.