Policy

Asos hack fears after thousands of shoppers sent sinister phone message

Oct 8, 2026 IDOPRESS

Asos is an online shopping website and app (Picture: Patrick/BFA.com/Shutterstock)

The ‘personal information’ of Asos shoppers may have been accessed after hackers sent customers a ‘threatening’ phone push notification.

The pop-up from the online shopping website’s app was sent at around 10am.

‘Dear Asos DPO and IT,we have fully compromised the Snowflake instance. Engage with us,or we will leak it,’ the message read.

The notification dinged on phones this morning

‘DPO’ refers to a data protection officer,who safeguards customer information. Snowflake is a cloud platform companies use to organise huge amounts of data.

Asos publicly commented on the ‘hack’ more than five hours later,describing it to Metro as an ‘unauthorised customer notification’.

It said customer names and contact details may have been nabbed,but not payment information or account log-ins.

The notification asked users to click a link to a Telegram channel; cybersecurity experts stressed to Metro that users should not access it.

The channel,called Xuanye gateway,asks users to join a broadcast channel,the Xuanye group.

Xuanye group said it obtained ‘customer information’ which does not include payment details.

The Telegram group which the push notification leads to

‘It is safe on our server and it will not be touched for a designated period,’ the group said in what it called its ‘final statement’ at about 2.50pm.

‘Considering the current situation regarding incident disclosure in the cyber security landscape,you can thank us for our generous clarity regarding this incident.’

What is the Xuanye group?

Sophos,a security software company which monitors the dark web,told Metro that the Xuanye group is ‘new’.

The group has so far not been mentioned on dark web forums,referring to the layer of the web that uses tech to hide a user’s identity and location.

Aiden Sinnot,principal threat researcher at the Sophos Counter Threat Unit,told Metro that it’s ‘not unusual’ for new hacking groups to spring up.

‘Often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with “credibility”,’ Sinnot said.

Asos says that it has 17 million customers each year (Picture: AFP)

Marijus Briedis,the chief technology officer at the software company NordVPN,told Metro that the notification is an ‘unusually brazen and threatening message’.

‘The attackers aren’t simply claiming to have breached ASOS,’ he said,‘they’re publicly telling the company to engage with them or they will leak what they say they have obtained.’

‘At this stage,however,customers shouldn’t assume their personal or payment information has been stolen – that hasn’t been established.’

Pieter Arntz,a researcher at Malwarebytes,also said it’s too early to tell how much data,if any,was nabbed.

‘Asos uses Simon AI for marketing,which runs on Snowflake,making the connection indirect,’ he says.

‘Any exposure could reveal a detailed customer picture,from browsing and buying habits to location and loyalty status. That’s valuable profiling data,though the connection alone doesn’t establish what attackers could actually access.’

Asos shoppers have been urged to change their passwords just in case,especially if it’s the same one they use for other apps and websites.

What has Asos said?

Asos said the app is safe to use (Picture: Getty Images)

Asos said that after the ‘unauthorised customer notification’ was sent out,it ‘immediately restricted access to the notification platforms’.

It said: ‘Basic personal information including name and contact details may have been accessed.

‘We do not believe that payment-card information or account passwords were impacted.’

Metro understands that the National Cyber Security Centre has offered support to Asos.

Snowflake told Metro that it has launched an investigation and found its platform has not been breached.

‘We take customer privacy and security very seriously,’ it added.

But for Aimee Speight,a communications expert and founder of Highland Consulting,how long it took Asos to issue a statement is troubling.

‘Right now,the hackers are doing a better job of communicating than Asos is,’ she added.

Simon AI has been approached for comment.

Get in touch with our news team by emailing us at .

For more stories like this,check our news page.