LiMP VPN
← All news

ASOS Hack: Extortion Sent via Push Notifications

ASOS Hack: Extortion Sent via Push Notifications

In short: On October 6, 2026, millions of users of British online retailer ASOS's mobile app received an unauthorized push notification titled "ASOS HACKED": unknown attackers claimed they had fully compromised the company's cloud data platform (Snowflake) and demanded contact via Telegram, threatening to leak the data. ASOS confirmed the notification was unauthorized and launched an investigation: preliminary findings suggest names and contact details may have been accessed, but not passwords or payment card data. The attack is linked to a previously unknown group calling itself XuanyeGroup.

What happened

At around 10:01 am UK time, ASOS app users began receiving a push notification seemingly addressed not to them but to the company's "DPO and IT" team: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it" — with a link to a Telegram channel for "negotiations". In effect, the attackers hijacked the retailer's own notification channel as a public ransom note — a rare, highly visible tactic aimed at maximum publicity. We've covered similar attacks on major brands on the LiMP VPN blog.

ASOS confirmed the notification was not authorized by the company and said it is investigating unauthorized activity involving third-party platforms used to message customers. According to the retailer, basic personal data — names and contact details — may have been accessed, but it does not believe payment card data or account passwords were affected. ASOS shares fell 10–15% on the news.

What is Snowflake, and who is XuanyeGroup?

Snowflake is a cloud platform for storing and analyzing large volumes of corporate data, used by thousands of companies worldwide. In 2025–2026, attackers used compromised Snowflake customer credentials to carry out a string of high-profile breaches at major brands — the pattern has become so recognizable that the platform itself responded quickly this time too: Snowflake stated its core infrastructure was not breached, and independent outlets such as Bloomberg could not verify that the attackers actually accessed ASOS customer data.

Researchers at KELA attribute the attack to a group calling itself XuanyeGroup — an actor with no established presence on major cybercrime forums or leak sites, which analysts say had recently been trying to launder money through high-value in-game items on Roblox and Counter-Strike. A lack of reputation on established criminal platforms doesn't by itself prove the claimed hack is a bluff, but it also doesn't confirm the scale of the claimed damage: the attackers have provided no public evidence that data was actually stolen.

What it means for shoppers

Even if the investigation ultimately shows less data was stolen than claimed, the fact that the message went out through the company's own official channel is itself a worrying signal: it shows attackers gained access to at least some part of the internal infrastructure used for customer communication. Names and contact details may sound harmless on their own, but leaks like this are exactly what fuels the next wave of phishing campaigns — disguised as "ASOS support" or an "order refund" notice.

If you're an ASOS customer (or a customer of any large online retailer), it's reasonable to assume your basic data may already be in third-party hands through no fault of your own — simply because the company you trust with your orders became a target.

How to protect yourself

First, don't click links in unexpected push notifications, emails, or texts "from ASOS" — especially ones demanding you urgently confirm something or visit a third-party site, since messages like that are typically how the next stage of an attack, phishing, gets launched. Check your order and account status only by opening the site or app yourself.

Change your ASOS password if you haven't recently, and — more importantly — make sure you're not reusing that same password anywhere else: mass breaches like this one fuel credential stuffing, automated attempts to try the same email-password pair across hundreds of other services. Enable two-factor authentication wherever it's available.

A separate layer of protection is controlling your own network traffic. The LiMP VPN app encrypts the connection between your device and the internet and hides from your ISP or a public Wi-Fi owner which sites and services you use — it won't stop a leak on the retailer's side, but it covers the network half of your privacy while you place orders or click links from emails at a café or airport.

Plans from 69 ₽/month, a verified no-logs policy: LiMP VPN pricing.

Sources