Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

ASOS confirms cyber incident following app notification sent by threat actors

Major online fashion brand ASOS has confirmed that it has been caught up in a cyber incident leading to customer data being impacted.

• Thu, 08 Oct 2026 •
ASOS confirms cyber incident following app notification sent by threat actors

In a filing with the London Stock Exchange, the British online retailer confirmed that ASOS customers were sent an unauthorised notification.

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us or we will leak it,” the notification read.

The notification was sent to app users in the UK, Australia, France, Sweden and the Republic of Ireland, according to local reports.

 
 

In its filing, ASOS said it was investigating the incident, including unnamed third-parties.

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities,” the filing reads.

“Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.”

ASOS confirmed that its operations and websites remained unaffected.

While the company did not disclose the threat actor behind the incident, the incident was claimed by a threat actor calling itself “Xuanye Group” on Telegram. While experts have said this points to a Chinese-speaking threat actor, the identity of the threat actor is still unclear.

While not much is known about the group, it did confirm that payment information was unaffected.

“To clear any confusion, the affected organisations app is safe to use,” the threat actor added.

“The incident involves customer information, it is safe on our server and it will not be touched for a designated period.

“Considering the current situation regarding incident disclosure, you can thank us for our generous clarity regarding this incident.”

ASOS said it could not quantify any impact on trading in its statement, but shares fell about a tenth earlier this week following news of the incident.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: