ASOS push notification hack warns shoppers to pause purchases

Thousands of ASOS app users received a fake alert about a Snowflake breach. The retailer says payment data is safe, but profile information may have been exposed. Here’s what happened and how to protect yourself.

A cracked phone, a paper snowflake, and a broken notification badge on a table representing a compromised push alert

Thousands of shoppers using the ASOS mobile app saw a push notification this morning that claimed the retailer’s data platform had been compromised. The alert, addressed to the company’s data protection officer and IT team, threatened to leak the Snowflake instance unless the attackers were engaged. ASOS confirmed the message was unauthorised, restricted the notification service and began an investigation.

Unauthorized push notification and its implications

According to Malwarebytes, the message was delivered through the app’s own notification infrastructure, which suggests someone gained access to the third‑party services ASOS uses for customer communications. The retailer’s marketing team employs Simon AI, a personalization engine that runs on Snowflake, together with Braze to trigger push alerts. Simon AI typically stores profiles that include browsing history, purchase history, demographic segments, and even geolocation and local weather data. If attackers accessed those systems, they could obtain a detailed picture of a shopper’s habits and preferences. The notification itself does not prove that the Snowflake instance was actually breached, only that an unauthorised party was able to send a message that appeared to come from ASOS.

Current facts from ASOS and investigators

Sky News reports that ASOS announced an “unauthorised customer notification” was sent at about 10 am local time. In a statement the company said it immediately limited access to the notification platforms and is working with specialists and authorities. ASOS added that basic personal information such as names and contact details may have been accessed, but it does not believe payment‑card data or account passwords were impacted. The Guardian reports the group behind the claim identifies itself as the “Xuanye group.” Their Telegram channel says payment information was not affected and that the app remains safe, but those statements have not been independently verified.

Possible consequences for shoppers

If the attackers obtained the profile data stored in Snowflake, they could use it to craft highly targeted phishing emails or messages that appear legitimate because they reference a shopper’s recent browsing or purchase activity. Such messages could trick users into revealing passwords, installing malware, or providing payment details on fake sites. Even without payment data, exposure of name, email, phone number and shopping preferences can increase the risk of identity‑theft and social‑engineering attacks. Because the push alert was delivered through the official app, users might be inclined to trust any future messages that appear similar, heightening the need for vigilance.

How to protect yourself now

  • Pause any pending orders on ASOS until the retailer confirms the issue is resolved.
  • Watch for unsolicited emails, texts or social‑media messages that reference the ASOS breach or ask for additional information.
  • Do not click links or download attachments from messages that claim to be from ASOS unless you verify them through the official website or app.
  • Consider removing the ASOS app temporarily; this blocks any further unauthorised push notifications.
  • Monitor your financial accounts for unexpected activity and report any suspicious charges to your bank.
  • Enable multi‑factor authentication on any online accounts that store personal data, especially email and banking services.
  • Review the security of your own website to see what information an attacker could already gather, see what an attacker can already learn about yours.
  • Use a reputable digital‑footprint scan to check whether any of your personal data appears online.

Lessons for small businesses and nonprofits

The ASOS incident highlights how reliance on third‑party marketing platforms can create a backdoor into customer communications. Even when a retailer’s core systems remain secure, an attacker who compromises a partner service can still reach users directly. Businesses should inventory every external service that can send messages to customers and enforce strict access controls. Regularly audit API keys, rotate credentials and limit permissions to the minimum needed. Establish a rapid response plan for unauthorised communications, including a clear public statement and steps to lock down the affected channels. Finally, educate customers about how official messages will look and where to verify alerts, reducing the success rate of phishing attempts that exploit a breach.

Staying aware of the tactics used in the ASOS push notification hack can help shoppers and organisations alike reduce risk and respond quickly if similar attacks arise.

Sources

This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.

Found this useful? Pass it on to someone who would want to know.

All Scam Alerts posts →

Cookie Notice

We use cookies to enhance your browsing experience and analyze site traffic. By clicking "Accept All", you consent to our use of cookies.