Thousands of ASOS customers received a push notification through the retailer’s app this morning that claimed a hack and threatened a data leak. ASOS said names and contact details potentially had been accessed, but it did not believe card data or account passwords were affected. According to Sky News, the retailer confirmed that an unauthorized notification went out at about 10 am today.
The message targeted ASOS’s data protection officer and IT team, claiming complete control of its Snowflake instance and demanding contact to prevent a leak. Malwarebytes Labs said delivery through the retailer’s app suggested someone had used its notification infrastructure without authorization. That delivery does not establish that the claimed Snowflake intrusion happened or that anyone stole customer data, Malwarebytes Labs cautioned.
ASOS said it was investigating unauthorized activity connected to outside platforms it uses for customer messaging. The retailer said it promptly curtailed access to those notification systems and was working with specialists and relevant authorities. Its website and app remained operational, and Malwarebytes Labs reported no verified evidence of theft involving customer databases, passwords or payment card information.
The retailer’s marketing operation uses Simon AI, a personalization service built on Snowflake, according to a Simon blog cited by Malwarebytes Labs. ASOS has described pairing Simon AI with Braze to tailor customer messages and trigger phone notifications. Snowflake provides cloud tools for storing data, processing it and carrying out analysis.
Simon AI says its typical customer profiles can include purchase records, browsing activity and demographic information, as well as location and weather. Those profiles can also distinguish Premier customers and people who have stopped purchasing. Malwarebytes Labs said exposure of such profiles could reveal shopping preferences and habits, while stressing that the description of ASOS’s marketing tools does not establish what attackers accessed.
The Guardian identified the party claiming responsibility as the Xuanye group, according to Malwarebytes Labs. On its Telegram channel, the group claimed payment information was unaffected and customers could safely use the app, but those assurances had not been independently verified. Malwarebytes Labs warned that stolen customer information could make targeted phishing more convincing and advised caution with unsolicited messages concerning ASOS or the incident.













