Skip to content

ASOS app hijacked to push Snowflake extortion message

On 6 October, ASOS customers got an in-app 'ASOS HACKED' push claiming a compromised Snowflake instance. Snowflake says its platform was not breached; the scope is unverified.

Published 3 min read

On the morning of 6 October 2026, customers of UK fashion retailer ASOS received a push notification from the retailer's own mobile app reading "ASOS HACKED," addressed to the company's DPO and IT team: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The message linked to a Telegram channel. ASOS shares fell sharply — reported at a double-digit percentage drop — as the alert spread.

What is confirmed and what is a claim matters here, so take them separately.

What ASOS confirmed

ASOS says there was unauthorized access to third-party communication platforms it uses, which is how the push went out. The company told customers to disregard the alert and said payment-card details and account passwords were not affected. It has not confirmed that any Snowflake environment was actually compromised, and has not disclosed how many customers may be affected.

What is only claimed

The attacker's assertion — a fully compromised Snowflake instance holding customer data — is unverified. Snowflake confirmed its core platform was not breached, consistent with the pattern seen in the 2024 Snowflake-tenant campaign, where the fault lay in customers' credential hygiene and missing MFA rather than Snowflake itself. As of writing, the only established fact is that someone used ASOS's app-notification pipeline to broadcast an extortion demand. The data-theft claim, its scope, and the actor's identity are all unconfirmed.

The actor

The group styles itself "Xuanye group" on Telegram. It is newly surfaced — not a name cyber-extortion trackers had on file before this week. Researchers at KELA, cited by The Record, say the same handle was recently seen attempting to launder funds through high-value in-game assets on Roblox and Counter-Strike, which argues against treating it as an established, capable ransomware crew on reputation alone. Attribution beyond the self-claimed name is not established.

What to do today

If you run a consumer app or own a cloud data warehouse:

  1. Lock down notification and messaging tooling. The breach vector here was a third-party comms platform, not the shopfront. Any vendor that can push to your users is a channel an attacker can hijack — enforce SSO, MFA and least privilege on all of them.
  2. Verify MFA on every Snowflake user, enforce network policies, and rotate any credential that could reach the warehouse. The 2024 campaign proved tenant credential theft, not a platform bug, is the realistic Snowflake risk.
  3. Have a pre-written holding statement for the case where an attacker reaches your customers before you do. ASOS was forced to respond through the same channel the attacker abused.
  4. Do not negotiate on the attacker's timeline. Treat an unverified "we have everything" claim as unproven until your own logs say otherwise.

Context

The move that makes this notable is not the alleged theft but the delivery: turning the victim's own app into the ransom note, reaching customers directly to pressure the company. It is extortion theatre optimized for a share-price reaction, and on that narrow measure it worked. The underlying question — was any Snowflake data actually taken — remains open, and the honest answer today is that we do not know.

Related stories