// 2 CRITICAL · 2 ZERO-DAY · 5 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
On October 6, 2026, ASOS customers received push notifications from the app bearing the signature 'xuanyewengateway' threatening to leak data from an alleged Snowflake compromise.

On October 6, 2026, thousands of ASOS customers found a push notification on their phones they never expected to see. The message, titled "ASOS HACKED," did not announce a promotion or a shipping delay: it issued a direct threat to the company's Data Protection Officer and IT team, citing the compromise of a Snowflake instance and urging them to "engage with us, or we will leak it." ASOS has not confirmed any breach as of the time of publication. The fact that attackers managed to use the app's official communication channel to deliver the threat turns this operation into a rare case of media weaponization in the cyber extortion landscape.

Key Takeaways
  • On October 6, 2026, ASOS customers received push notifications from the app titled "ASOS HACKED" with text threatening to leak data from an alleged Snowflake compromise
  • The message was signed "xuanyewengateway" and contained a link to a Telegram channel for the "Xuanye Group," created the same day as the attack
  • ASOS has not confirmed any compromise: the source does not verify the attackers' claims regarding the technical scope of the incident
  • The ability to send push notifications requires access to systems distinct from the Snowflake data platform, according to Horizon3 analysis cited by the BBC
  • ASOS shares fell more than 10% in the morning, up to roughly 13% according to The Independent, in the absence of official breach confirmation

The Notification Content and the Group's Signature

The full text of the push message, reported by Infosecurity Magazine, read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The signature was "xuanyewengateway," with a link to a Telegram channel. The Independent identified the group as the "Xuanye Group," with a channel created on October 6, 2026, the date the notifications were sent. No prior history of this group emerges in the dossier.

Addressing the DPO and IT, rather than customers as primary recipients, indicates the push notification was designed as a pressure message toward the company. Customers were the vehicle, not the target. This tactical choice turned every app user into an unwitting witness to the extortion, amplifying the psychological and media effect.

The Indirect Snowflake Connection and the Cloud Supply Chain Problem

ASOS uses Simon AI for marketing, a platform that runs on Snowflake. The connection between the British e-commerce company and the allegedly compromised cloud instance is therefore indirect: it is not a direct ASOS-Snowflake contract, but a chain of cloud services that includes an intermediary.

The central issue, raised by Dan Bird of Horizon3 in a comment to the BBC, concerns the technical separation between systems: "Sending a push notification to ASOS's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised." If both claims were true, it would imply the attackers obtained operational credentials across multiple connected systems. The dossier does not verify that both compromises actually occurred.

The Stock Plunge Absent Official Confirmation

The market impact was immediate and severe. According to Cybernews, at 9:50 GMT on October 6, ASOS shares had lost more than 10%. The Independent reported a drop of roughly 13% in the morning. This reaction occurred in the absence of any official confirmation from ASOS or Snowflake regarding the breach, and despite Reuters stating it could not independently verify the reports, as noted by Eastern Eye. More than 400 people reported issues on Downdetector by 10:30 on October 6, though these reports do not equate to a direct measure of the hack notification's receipt.

The financial data takes on relevance in an already fragile context for the company. According to The Independent, ASOS counts roughly 17 million annual customers across more than 150 countries, with 2025 revenue of £2.5 billion, down from £2.9 billion previously, and an operating loss of £212 million in the last year. The absence of financial margin for error makes the reputational damage of this operation particularly heavy, regardless of the technical verification of the attackers' claims.

"The attackers didn't just steal from ASOS. They used ASOS's own voice to tell its customers. This is a complete loss of operational control, and the reputational damage from that fact alone is significant."
— Muhammad Yahya Patel, Huntress, quoted by Cybernews

The Forced Publicity Tactic and the Extortion Calculus

Analysis by Aras Nazarovas on Cybernews highlights the strategic paradox of the operation: "Publishing the message via notifications to users is a double-edged sword here, as that might have a similar effect as an internal message, but now everyone knows about the breach, which greatly reduces the likelihood of the ransomware payment actually being made." The public visibility of the threat, obtained through a customer communication channel, reduces the room for maneuver in any secret negotiations.

Jake Moore of ESET, cited by Infosecurity Magazine, underscored another aspect: "The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS's connected systems, but it doesn't prove their full claims about the extent of the data breach." This distinction is crucial: access to the notification system is documented by the very existence of the pushes sent; the full compromise of Snowflake remains an unverified claim.

What to Do Now

For ASOS customers, the dossier does not indicate specific actions required by the company. Independent verification of the attackers' claims, in this case not performed by Reuters, remains a critical point for crisis management. Companies managing cloud data platforms connected to customer communication systems must assess the actual separation between data layers and engagement layers, given the added complexity from intermediaries like Simon AI in the service chain.

Monitoring the "Xuanye Group" Telegram channel represents the only public source of updates from the attackers, though its reliability is unverified. ASOS has not communicated timelines for any official updates as of the time of publication.

Why It Matters

The ASOS case of October 6, 2026 illustrates a tactical evolution in cyber extortion: the conversion of the customer communication channel into a megaphone for public pressure. The push notification has distinctive characteristics: it reaches personal devices with an immediacy a website lacks, exploits the legitimacy associated with the official app, and generates viral screenshots on social media that extend the threat's life beyond the initial receipt.

The brief does not document specific remedial measures adopted by ASOS at the time of the incident. The source does not specify the nature of any data potentially exposed, nor whether ASOS has paid or intends to pay a ransom. The dossier does not clarify whether ASOS is a direct Snowflake customer or only indirect via Simon AI, and does not verify whether the previous breach of over 100,000 US ASOS customer accounts, cited by Cedar News, connects to the current incident.

Information is based on cited sources and current as of publication.

Sources


Sources and references
  1. infosecurity-magazine.com
  2. cedarnews.net
  3. cybernews.com
  4. the-independent.com
  5. bbc.com
  6. easterneye.biz
  7. warringtonguardian.co.uk
  8. nexos.ai