British online fashion retailer ASOS has confirmed a data breach involving customers’ personal information after hackers exploited the company’s notification system to alert users that its data had been compromised.
In a filing with the London Stock Exchange, ASOS disclosed that attackers gained access to a third-party platform hosting data used to communicate with customers. The company confirmed that names and contact details were among the information stolen.
According to BBC News, the compromised data also includes customers’ home addresses, phone numbers, email addresses, and profile-related notes, including website search queries.
The incident became public after hackers sent an unauthorized notification through ASOS’ own app. Messages shared on social media showed the attackers addressing the company’s data protection officer and IT department, claiming they had gained full access to customer information hosted on Snowflake, a cloud-based data platform used by businesses to store and analyse large volumes of information.
The message reportedly warned ASOS to engage with the attackers or risk having the stolen data published online. By using the retailer’s own communication system to notify customers, the hackers appear to be applying pressure on the company to respond to their demands.
According to BleepingComputer, the attackers, identified as Xuanye Group, reportedly gained access by impersonating a trusted contact to obtain login credentials. Snowflake has stated that its systems were not breached, suggesting the incident may have involved compromised credentials or access to an individual customer’s environment rather than a direct attack on Snowflake’s infrastructure.
However, it remains unclear whether ASOS’ Snowflake environment was protected by multi-factor authentication or how the attackers accessed the system used to send in-app notifications, a process that can involve third-party service providers.
ASOS has not disclosed the total volume of information stolen or confirmed how many customers were affected. The company has approximately 17 million customers, according to its website, although the number potentially impacted by this incident remains unknown.
The breach follows a similar incident involving financial technology company Betterment in January 2026. In that case, hackers reportedly accessed a third-party marketing platform and used it to send fraudulent cryptocurrency-related messages to customers while also obtaining personal information, including names, email addresses, and phone numbers.
The ASOS incident highlights the cybersecurity risks associated with third-party platforms and stolen login credentials. It also demonstrates how attackers can exploit legitimate company communication channels to make fraudulent or threatening messages appear authentic, potentially increasing pressure on businesses while undermining customer trust.



































