BREACH WATCH BRIEF High 📱 Breach

Attackers Hijack ASOS Mobile App to Display Fake ‘Store Hacked’ Notification

Attackers injected a fraudulent pop‑up into the ASOS shopping app, claiming the retailer’s Snowflake data warehouse was compromised and warning customers of a breach. The incident highlights gaps in oversight of third‑party communication services and the need for continuous control‑assurance evidence around vendor access.

SeverityHigh
Type📱 Breach
ConfidenceHigh
ReportedOct 7, 2026
Retail & E-Commerce Retail/E‑commerce (ASOS) and its 17 million customers worldwide Third-Party Dependency Other
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

A group calling itself Xuanye posted a fake ‘ASOS HACKED’ message through the retailer’s mobile app, alleging compromise of its Snowflake instance and demanding a ransom. ASOS confirmed unauthorized activity involving third‑party platforms used for customer communications and began restricting access while investigating.

Why it matters for trust and compliance

  • The event underscores the importance of continuous monitoring of third‑party services and maintaining auditable evidence of vendor access controls, a core control objective across many frameworks.
  • Demonstrates need for continuous vendor‑access monitoring to satisfy audit evidence requirements
  • Supports mapping of third‑party oversight controls to multiple frameworks (e.g., NIST CSF, ISO 27001)

Who is affected

Retail/E‑commerce (ASOS) and its 17 million customers worldwide

Recommended actions

  1. Review and harden access controls for all third‑party notification and data‑warehousing services
  2. Collect and retain logs of vendor interactions as evidence for audit readiness

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.