Overview
- Thousands of ASOS app users received a push notification on Tuesday titled “ASOS HACKED” that told the company’s DPO and IT team their Snowflake environment was ‘fully compromised’ and linked to a Telegram channel called Xuanye.
- ASOS says it is aware of the reports and is investigating but has not confirmed that any Snowflake account or customer data were accessed.
- Security firms and researchers say the ability to send the alert from ASOS’s official app points to unauthorized access to the retailer’s notification infrastructure or to credentials that span multiple systems.
- The alert coincided with hundreds of outage reports on Downdetector and a sharp market reaction that sent ASOS shares down about 10–12% in London trading.
- Experts urge customers not to click the Telegram link, to watch for phishing attempts, and note that UK data‑breach rules require firms to report confirmed personal‑data breaches to the ICO within 72 hours.