ASOS Customers Receive Threatening Notification in Suspected Hack
Article Content
- •ASOS customers received a push notification claiming a data breach on October 6, 2026.
- •The notification threatened to leak data unless the company engaged with the hackers.
- •ASOS is investigating the incident, and its stock price fell nearly 12% following the notification.
On October 6, 2026, ASOS customers received alarming push notifications claiming that the company's systems had been hacked. The message, addressed to ASOS's data protection officer and IT department, stated, 'Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' The notification included a link to a Telegram channel created by the alleged hackers, known as the Xuanye Group. ASOS has not confirmed whether a breach has occurred and is currently investigating the situation. The incident has raised concerns about the potential exposure of customer data, although the hackers claimed that payment information was not affected. Following the notification, ASOS's stock price dropped nearly 12%. Experts warn that the public nature of the threat could lead to phishing attempts targeting customers. The exact number of affected users is unclear, but reports indicate that thousands received the notification.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (23)
Following this threat?
Track Xuanye Group and ASOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data may have been compromised?
What should ASOS customers do now?
Is ASOS's website still safe to use?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…