Trusence Every claim has a source
Last updated 6 October 2026 Search Türkçe
← All stories
Security

ASOS says a mobile-app incident exposed customer contact details

The retailer has told shoppers to ignore a malicious in-app alert while it checks an unauthorized access incident affecting customer communications.

ASOS says a recent mobile-app incident exposed unauthorized access to third-party customer communication systems, and it has warned shoppers not to use the malicious in-app alert sent through its app. The retailer says basic personal details such as names and contact information may have been exposed, but it has not confirmed the attackers’ claim that its Snowflake environment was breached or said how many customers were affected. ASOS also says it does not believe payment-card data or account passwords were compromised. The alert began appearing around 5:00 a.m. ET on Tuesday and was linked to a Telegram channel used by a group calling itself the Xuanye group, which later claimed it stole customer information.

Why it matters

For shoppers, the immediate change is that ASOS says some basic personal details may have been exposed, but card data and account passwords were not likely affected. The company has not confirmed a wider compromise or how many customers were involved, so affected users still do not know the scale of the incident or whether they need to take further action beyond ignoring the alert and link.

Sources

  • BleepingComputer