Skip to content
REALNEWS HUB

ASOS app users receive push notifications apparently sent by hackers

Dozens of people appear to have received a strange message from the clothing and beauty store's app.

REALNEWS HUB Newsroom

Oct 6, 2026, 20:02 UTC

A person holds a glowing smartphone showing generic push notifications in a dimly lit modern room.
REAL NEWS HUB

Online fashion retailer Asos has launched an investigation into unauthorized activity after users received unexpected push notifications on their mobile devices apparently delivered by cyber criminals. The incident caused the firm's share price to drop by roughly 10% on Tuesday as technical teams worked to contain the issue.

The alert, which arrived on customer devices on Tuesday morning, carried the title "ASOS HACKED" and was addressed directly to the British company's IT staff and data protection officer. In the message, the attackers claimed to have compromised an environment associated with data analytics provider Snowflake, threatened to publish stolen material if the company did not make contact, and included a link directing readers to a channel on Telegram.

Following the intrusion, Asos sent a message to shoppers offering an apology and urging recipients to ignore the notification. The retailer stated that it took immediate steps to restrict access across its messaging services and brought in external experts alongside relevant authorities to manage the response. The company indicated that while basic personal details may have been accessed, it does not believe that passwords or bank card details were compromised. Asos maintained that its website and shopping application continue to run normally.

The reach of the unauthorized alert extended internationally, with recipients reported in countries such as Australia, Ireland, France, and Sweden, in addition to the United Kingdom. Although the precise number of impacted users has not been confirmed, the retailer serves about 17 million active shoppers worldwide, and its Android application alone records over 10 million downloads.

Experts in computer security described the tactic of using an organization's own customer communications infrastructure as an unusually visible extortion effort. While traditional blackmail attempts are conducted privately, sending ransom demands directly to consumers increases pressure on corporate management. Analysts noted that sending push notifications requires access to a separate platform from Snowflake, suggesting the perpetrators may have gained unauthorized access to credentials across multiple systems.

Snowflake stated that its internal review is ongoing and that it has discovered no evidence of an intrusion into its core platform. In the meantime, the UK National Cyber Security Centre has made offers of support to Asos. The retailer has not officially notified the Information Commissioner's Office, the country's privacy regulator, regarding a confirmed breach.

Security specialists advised worried consumers not to click any links found within the rogue notification, to maintain vigilance against phishing attempts or unsolicited messages, and to consider updating passwords across their personal accounts as a precaution.

Source & verification

Verified

Reported from Business.

Get breaking news alerts and the Morning Briefing

Verified stories in your inbox, every one linked to its sources. All newsletters →

Newsletters

Free. Unsubscribe any time. See our privacy policy.