British online fashion retailer ASOS has confirmed a cyberattack after UK customers began receiving unauthorized push notifications on the company’s mobile app reading “ASOS hacked.” The message demanded that ASOS engage with the attackers or risk having stolen data leaked, and referenced a compromised Snowflake instance.

In a filing with the London Stock Exchange, ASOS confirmed that a third-party platform used for customer communications was hacked, allowing the unauthorized notifications to reach users’ devices. The company said it took immediate action to restrict access to the notification platform and is working with internal and external specialists as well as relevant authorities.

ASOS said hackers may have accessed basic customer information, including names and contact details, but stated it does not believe payment card data or account passwords were compromised. The company said its website and app remain unaffected and that operations have not been disrupted. ASOS has not disclosed which specific platform was breached or confirmed the attackers’ claim regarding Snowflake.

Possible Snowflake Connection

Security researchers noted parallels to the 2024 campaign in which the ShinyHunters group compromised more than 160 organizations’ Snowflake instances using credentials harvested from infostealer malware, later using the stolen data for extortion. Forescout Research Vedere Labs VP of research Daniel dos Santos said the ASOS incident could follow a similar pattern, though the initial access method has not been confirmed.

A group calling itself Xuanye Group claimed responsibility via a newly created Telegram channel. Dos Santos noted the name suggests a Chinese-speaking threat actor but cautioned this could be a false flag.

A Deliberate Publicity Play

Talion Cyber Security head of threat intelligence Natalie Page said directly messaging customers through the ASOS app is a notable tactic aimed at generating publicity, a common extortion technique used to pressure victim organizations through media attention. Page added that if the breach is confirmed to involve a Snowflake vulnerability, it should be investigated urgently to determine whether other organizations using the platform could be similarly affected.

ASOS has not named the compromised third-party vendor or confirmed attribution. The investigation remains ongoing.