On the morning of October 6, 2026, shoppers across the United Kingdom, Australia and beyond woke up to a notification they never wanted from their favorite shopping app. Instead of a sale drop, the hijacked ASOS Push Alerts carried a ransom note written for the retailer's own IT team. Two days later, ASOS told customers the uncomfortable truth about how the breach really began — an attacker impersonating a trusted contact had talked an employee out of their login credentials.

The rogue message had claimed a full compromise of ASOS's Snowflake data environment. The real attack was more human: stolen credentials reused against third-party platforms. With roughly seventeen million active customers across more than a hundred markets, the fallout from the hijacked ASOS Push Alerts could reach a huge slice of Gen Z's favorite fashion app.

How the ASOS Push Alerts Became a Ransom Note

Around ten o'clock London time on October 6, a third-party notification platform used by ASOS sent a message titled "ASOS HACKED" to app users in several countries, according to the company's update to investors. The note was not addressed to shoppers at all. It read, in part: "we have fully compromised the Snowflake instance. Engage with us, or we will leak it," followed by a link to a Telegram channel, as reported by Help Net Security. The note was signed "xuanyewengateway" and pointed to a channel run by a group calling itself Xuanye Group.

The rogue ASOS Push Alerts reached customers in the UK, Australia, France, Sweden, Ireland, the United States and Germany, with some versions in English and Hebrew reaching Israeli shoppers too. As BBC cyber correspondent Joe Tidy noted, the ASOS Android app alone has been downloaded more than ten million times, so it is likely that millions of shoppers saw the extortion message on their lock screens.

Most data breaches surface through a carefully worded company statement or a leak-site post. This one arrived upside down: the ASOS Push Alerts hit customers' phones before ASOS had said a word publicly. As ESET global cybersecurity adviser Jake Moore told Computer Weekly, the incident was "one of the most visible hacks in history." Shares slid sharply in London trading as the news spread.

ASOS Push Alerts and the Snowflake Claim That Crumbled

For two days, the biggest open question was whether the attackers had really gotten into ASOS's Snowflake environment, the cloud platform where the retailer's customer data sits. The rogue message insisted the "Snowflake instance" was fully compromised, and the group's Telegram posts claimed payment information had not been touched and the data would be left alone for a set period, according to BBC reporting relayed by Computer Weekly. None of it was independently verified.

On October 8, ASOS gave customers a different answer. The company said an unauthorized party had gained access to an employee account by "impersonating a trusted contact to obtain login credentials," then used those credentials to pull data from certain third-party platforms, as reported by CosmicBytez Labs in its October 8 analysis. That is a classic pretexting attack: no software flaw, no brute-forced database — just a convincing impostor and one working login.

Snowflake, for its part, denied any platform compromise. According to Help Net Security, the company told the BBC its investigation had found "no compromise" of its platform, and in an October 9 statement it added that the incident did not result from any vulnerability or flaw in its service. The attackers' headline claim has effectively been discredited, though ASOS has not formally ruled out every angle. ASOS says it does not believe payment-card information or account passwords were impacted; it believes names and contact details may have been accessed. The investigation is ongoing. For the latest on the industry's dramatic week, follow the fashion topic page.

What Shoppers Should Do After the ASOS Push Alerts Hijack

The scariest part of this story is not the ransom note — it is what comes next. The categories ASOS says may have been accessed, names and contact details, sound boring until you realize how they get used. An attacker holding a name, phone number, delivery address and recent search history can write a fake order update or "parcel held" text that looks completely legitimate. That is the follow-up wave to watch for.

ASOS told customers there is no action needed on their accounts, but advised staying alert for unexpected messages or calls claiming to be from the retailer. The company's guidance is blunt: it will never ask shoppers to share passwords, security codes or payment details through an unsolicited message or call. Shoppers who got the alert should not click the Telegram link or message the group, and anyone can check their orders by opening the ASOS app directly instead of following a link in a text, according to ThaiCERT, which advises relying only on the company's official website or app.

Good hygiene still applies. If you reused your ASOS password anywhere else, change it there first; switch on two-factor authentication; and keep an eye on card statements even though ASOS says card data was not taken. A longer checklist of post-breach steps is available, according to a consumer guide from PrivacyOn, which also notes this is a different incident from the separate August 2026 ASOS breach in the United States that affected nearly one hundred forty thousand people and did involve financial information.

Why a Push-Alert Hijack Stings Differently

Retail breaches usually come in whispers; this one arrived as a shout. By hijacking the ASOS Push Alerts, the attackers burned the trust of the channel itself — the same notifications shoppers rely on for order updates and sale drops now double as proof that the app can be made to say anything. It is an extortion tactic designed to pressure the company by embarrassing it in front of its own customers.

The October breach also followed an August credential incident affecting ASOS's United States operation — a rough stretch for the retailer's security team. The UK's National Cyber Security Centre has offered ASOS assistance, and ASOS says additional security measures are already in place while it works with experts, law enforcement and regulators. For a retailer built on the trust of young shoppers who live on their phones, the lock screen turned out to be the loudest — and riskiest — megaphone of all. It has been a bruising stretch for fast fashion generally; see this report on France fining fast-fashion items up to twelve euros apiece.