A push notification headed “ASOS HACKED” reached app users in five countries on Tuesday morning. The retailer says its site and app are operating normally. The uncomfortable question for every board is what the attackers reached in order to send it.

At around 10:00 on Tuesday 6 October, Asos customers in the UK, Australia, France, Sweden and Ireland opened their phones to a notification from the retailer’s own app. It was headed “Asos hacked”, addressed to the company’s data protection officer and IT teams, and read:
“We have fully compromised the Snowflake instance. Engage with us, or we will leak it.” A link pointed to a Telegram channel (BBC News, 6 October 2026).
The Asos app has been downloaded more than 10 million times on Android alone, and the company serves around 17 million customers a year across more than 150 markets (BBC News).
Asos said it was investigating “unauthorised activity involving third-party platforms that we use to communicate with customers”, that it took immediate action to restrict access to the notification platforms, and that basic personal information including name and contact details may have been accessed. It does not believe payment-card records or passwords were compromised (The Guardian, 6 October 2026).
Snowflake told the BBC its investigation had found “no compromise” of its platform.
Shares fell by more than 14% intraday and closed down 9.56%. The company disclosed that it holds cyber insurance with a large global provider, including business continuity cover, while noting it is “too early to quantify any potential impact on trading” (The Guardian; Asos statement to the London Stock Exchange). The National Cyber Security Centre is offering assistance.
None of the attackers’ claims have been verified, and the picture may change. Four things are already clear enough to act on.
The breach was in the plumbing, not the shopfront
Asos’s statement points at third-party platforms used to communicate with customers. The website, the app and payments appear to have held. What didn’t hold was something adjacent — a notification capability sitting outside the perimeter most security programmes are built to defend.
How far that access extended is genuinely contested, and the disagreement is instructive. Dan Bird of Horizon3 told the BBC that sending a push notification would require access to Asos’s notification system, which he described as separate from the Snowflake data platform: “If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door” (BBC News). The Guardian, meanwhile, reports that Snowflake itself enables push notifications to phones, which would mean a single compromised instance could do both (The Guardian).
Either reading lands in the same place for a risk function. A platform most organisations would classify as analytics infrastructure turns out to sit on the path to every customer they have. Most organisations can describe their own controls in detail. Far fewer can say which of their suppliers could message their entire customer base.
Extortion moved from the back room to the shop window
Ransom negotiations normally happen in private, with a window before anything becomes public. Here the attackers skipped that and used the company’s own customer channel as the ransom note. Charlotte Wilson, head of enterprise at Check Point, called it “deeply serious” and “brazen”, describing it as hackers turning Asos’s own app into their ransom note (BBC News).
Dray Agha, senior manager of security operations at Huntress, was blunter: “Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation” (The Guardian).
The group behind it, calling itself the Xuanye Group, was unknown before Tuesday. Sophos could find no prior mention of it on hacker forums or Telegram channels. Its principal threat researcher Aiden Sinnott noted that new groups often wait until they have what they see as a significant opportunity before announcing themselves, “so as to enter the ecosystem with ‘credibility’” (The Guardian). A newcomer chose a listed consumer brand and a public channel as its introduction, which tells you what the tactic is worth.
Incident response plans written around a private negotiation window have just been tested against a scenario that doesn’t offer one.
The second wave arrives before the facts do
Every expert quoted this week said the same thing: the phishing follows. Marijus Briedis, chief technology officer at NordVPN, warned that criminals may exploit the publicity by sending emails and texts claiming to be from Asos, “perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund” (The Guardian). Those messages land while customers are still unsure what happened, which is precisely when they work.
The NCSC’s chief executive, Dr Richard Horne, framed the wider point: the unauthorised notification “has brought into the light how cyber incidents do not simply affect big business but can have repercussions for individuals much more widely too” (The Guardian).
This is now a sector pattern
Asos follows Marks & Spencer, the Co-op and Harrods, all of which suffered cyber incidents last year. M&S and the Co-op saw stock shortages, and M&S was forced to close its website for several weeks while it worked to ensure its systems were clean (The Guardian).
The national picture matches. The NCSC’s most recent Annual Review records 204 nationally significant cyber incidents in twelve months, up from 89 the year before — an average of four a week — with highly significant incidents rising roughly 50%, the third consecutive annual increase (NCSC).
The direction of travel isn’t in dispute. What’s in dispute inside most organisations is who owns the parts that sit between functions: the supplier nobody mapped, the platform nobody classified as critical, the comms plan written for a slower kind of crisis.
Where these conversations happen
Those gaps are what #RISK Expo Europe exists to close. On 10–11 November at ExCeL London, practitioners who have run these incidents work through them in public:
- Supply Chain Risk: Visibility, Concentration and the Limits of Due Diligence — Wednesday 11 November, 12:00, RISK Stage, with Teodora Pimpireva Tapping of UNiDAYS, previously at Meta, Google, Mastercard and Bumble
- Governing Third-Party Risk: Closing the Accountability Gap Between Procurement, Security and the Business — Wednesday 11 November, 12:50, GRC Stage
- Ransomware, Geopolitics and Critical Infrastructure: Preparing for the Worst Day — Wednesday 11 November, 10:00, RISK Stage
- AI and Cloud Concentration Risk: The Governance Questions Boards Can No Longer Defer — Tuesday 10 November, 11:20, RISK Stage
- The Cyber Security and Resilience Bill: What It Means for Your Business — Tuesday 10 November, 12:50, RISK Stage, with Duncan McDonald, CISO at NCC Group, and Florian Pouchet of Wavestone
Risk. It’s everyone’s business — and this week, it was everyone’s push notification.



No comments yet