Asos is investigating what it describes as unauthorised activity involving third-party platforms used to communicate with customers, after shoppers received an alarming push notification that appeared to come from attackers rather than the retailer.
The message, addressed to Asos’s data-protection and IT teams, claimed that the company’s Snowflake instance had been fully compromised and demanded engagement under a threat to leak data. It linked recipients to a Telegram channel said to be operated by a group calling itself Xuanye Group. The name was reportedly not widely known in cybersecurity circles.
Asos says it moved immediately to restrict access to the notification platforms, and that it is working with internal and external specialist advisers and the relevant authorities. Its app and website remain operational.
The retailer has warned that customer names and contact information may have been accessed. At this stage, however, Asos says it does not believe payment-card details or passwords were compromised. That distinction matters, but it does not make the incident trivial: names, email addresses, phone numbers and other contact details can still be useful to scammers attempting highly convincing follow-up messages.
What happened, and what remains unconfirmed
The most visible aspect of this incident was the use of a customer-facing push-notification channel. A push notification is the alert displayed by an app on a phone or other device. It is normally used for routine messages such as delivery updates, offers or account activity. Here, it became a public delivery mechanism for an extortion demand.
The alert itself is evidence that somebody obtained the ability to send messages through a platform connected to Asos’s customer communications. It is not, by itself, proof of every claim made in the alert. Attackers frequently make broad assertions during extortion attempts, while affected organisations must investigate what systems were accessed, which information was reachable and whether data was actually taken.
That is why the language in Asos’s statement is important. The company is investigating unauthorised activity involving third-party platforms, has restricted access to notification services, and has identified a potential exposure of names and contact information. It has not said that passwords or payment details were compromised, and it says it does not believe they were. Until an investigation establishes more, shoppers should treat both the attackers’ claim and the scope of the incident with appropriate caution.
Snowflake and the third-party platform question
Snowflake is a cloud service used to work with data, including information connected to transactions and customer demographics. Cloud services are operated by specialist providers rather than being hosted entirely inside a company’s own infrastructure. Businesses commonly connect them to other tools for analytics, marketing and customer communications.
That setup can be useful, but it also means an incident may involve several separate systems and permissions. A notification platform may be able to reach an app audience; a data platform may hold records used to analyse customer activity; another service may manage account authentication. The presence of a push alert does not establish which of those systems were accessed, what permissions were used, or whether the alleged access extended as far as the attackers claimed.
In practical terms, “third-party platforms” means the investigation is likely focused not only on Asos’s own services, but also on the tools that help it contact customers. Restricting access to the notification platforms was therefore a sensible immediate containment measure: it aims to stop further unauthorised messages while the affected connections and accounts are examined.
Consumers regularly encounter this kind of connected-service arrangement without seeing it. Shopping apps, games, social platforms and photo services often rely on multiple cloud and communication providers behind the scenes. Understanding which app handles an image library or cloud storage, for example, is a practical part of controlling personal information online; our guide to Google Photos and Google Gallery explores a similarly useful distinction between an on-device app and cloud-linked services.
Why contact information can still be valuable to scammers
When payment details and passwords are not believed to be affected, the immediate risk is different from a case where criminals can directly attempt account takeovers or fraudulent purchases. But contact information can enable social engineering.
Social engineering is the use of misleading messages or impersonation to persuade someone to disclose information, click a link, install something, or make a payment. A scam becomes more persuasive when it contains real details such as a person’s name, an email address or the fact that they use a particular retailer.
That does not mean every Asos customer will receive a scam, or that every unsolicited Asos-themed message is malicious. It means shoppers should expect the possibility of opportunistic follow-ups that refer to a supposed breach, refund, order issue or security check. Attackers may try to exploit anxiety around a real event to give a fake email, text or notification the appearance of legitimacy.
The Telegram link in the push alert deserves particular care. A link sent during an alleged breach can be part of an attempt to publicise an extortion group, pressure the affected company, collect attention, or draw people toward material they should not engage with. Customers have no need to visit it to protect an account or understand the incident.
What Asos customers can do now
Because Asos says it does not believe passwords or payment details were compromised, there is no stated evidence that customers need to reset passwords solely because of this event. Still, this is a good moment for cautious account hygiene. The goal is not panic; it is reducing the chance that an attacker can turn exposed contact information into something more serious.
- Be sceptical of unexpected messages. Treat emails, texts and alerts claiming to be from Asos with extra care, particularly if they demand urgent action, offer compensation, or say an account must be “verified.”
- Do not use links in unsolicited messages. If an order or account needs attention, open the Asos app yourself or type the retailer’s known website into a browser rather than following a link from an email, text or notification.
- Never share a password or verification code in response to a message. A one-time code can be as sensitive as a password when it is used to sign in or approve an account change.
- Use a unique password for every important account. Unique credentials limit the damage if a password from some other service is ever exposed. A password manager can help generate and store them.
- Review messages for signs of impersonation. Unusual sender addresses, awkward wording, a request for payment, or pressure to act immediately are common warning signs. Familiar branding or a correct name should not be treated as proof that a message is genuine.
- Watch for official updates through channels you open yourself. Asos has said its website and app are operating as usual, so customers can check those services directly rather than relying on forwarded posts or screenshots.
Customers who reuse an Asos password elsewhere may also choose to replace it as a broader precaution, even though Asos does not believe passwords were compromised. The most important rule is to make the replacement unique, rather than changing it to a small variation of an existing password.
Push notifications are trusted—and that is the problem
This episode also illustrates why a compromised notification channel can be so disruptive. People tend to see a push alert as more immediate and more trustworthy than a promotional email. It appears on a device already associated with the app, often with the app’s name and icon. That makes it an unusually effective route for both legitimate customer updates and unauthorised messages.
For companies, the operational lesson is not that push notifications are inherently unsafe. Rather, systems that can contact a full customer base warrant strict access controls and rapid ways to revoke access. For customers, the lesson is to assess the content of an alert, not merely its delivery route. An unexpected notification that directs people to an external channel, requests sensitive information or creates urgency should be independently verified.
Asos has already said it restricted access to the relevant notification platforms and brought in specialist advisers. The investigation will determine whether the possible exposure was limited to names and contact details, whether other data was involved, and how the unauthorised activity occurred. For now, the confirmed practical picture is narrower than the attackers’ dramatic claim: an unauthorised message reached shoppers, Asos is investigating third-party communication systems, and the company says payment details and passwords are not believed to have been compromised.
That leaves customers with a straightforward response: do not interact with breach-themed links or unsolicited support messages, use official routes to check an account, and remain alert to impersonation attempts that may use the incident as cover.






