INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ASOS Hackers Hijack App Notifications Claiming Snowflake Data Breach

| 2026-10-06 21:56 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On October 6, 2026, British online fashion retailer ASOS received a threatening notification from hackers claiming to have compromised the Snowflake instance and demanding engagement or data leakage. The attackers used ASOS's official mobile app to send notifications directly to customers, warning of impersonation and providing instructions on how to access their legitimate broadcast channel. The hackers claimed that customer information held on ASOS's server was safe but may have included names and contact details accessed by the attackers; however, payment-card information or account passwords were not impacted. ASOS restricted access to affected notification platforms, began working with cybersecurity specialists and relevant authorities, and acknowledged receiving an unauthorized push notification from customers.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in- • Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA retailretail
Incident Timeline
‎October 6, 2026
Threat actors, claiming to be the Xuanye Group, hijacked app notifications on customers' phones and posted a link to their Telegram channel.
industry Retail
organisation National Cyber Security Centre
organisation Screenshots
organisation Snowflake
organisation Telegram
organisation Xuanye Group
organisation Hackread.com
organisation Xuanye Group’s
organisation Reuters
organisation AT&T
organisation Ticketmaster and Santander
victims 165 Snowflake customers
organisation ASOS
Tactical Metrics
Metrics
victims
165
Snowflake Customers
Intelligence Sources