ASOS Confirms Breach After Attackers Hijack In-App Push Notifications, Claim Snowflake Data Theft
What happened
UK fashion retailer ASOS has confirmed a data breach after attackers sent unauthorized "HACKED" push notifications through its mobile app, according to BleepingComputer. The attackers claimed to have stolen customer data from ASOS's Snowflake environment. At the time of reporting, the scope of the exposed data and the attackers' exact method of entry had not been fully detailed by ASOS.
Why it matters
This fits a pattern seen across multiple retail and consumer brands in 2026: attackers compromising a Snowflake-connected environment (often via stolen or reused credentials on accounts lacking MFA) to exfiltrate customer data, then using an owned customer-facing channel — here, mobile push notifications — to publicize the breach and pressure the company. For defenders, the notable risk isn't just the data exposure itself but the loss of control over a trusted first-party communication channel, which can be reused for phishing or further social engineering against customers.
What defenders should watch for
- Audit third-party data warehouse (Snowflake or equivalent) access: enforce MFA on all accounts, rotate credentials tied to service/integration accounts, and review network policies restricting connections to known IP ranges.
- Review who/what has permission to trigger push notifications or messaging campaigns from your mobile app backend — treat this as a privileged capability, not just a marketing function.
- Hunt for anomalous query volume, unusual export/COPY INTO activity, or logins from unfamiliar locations/ASNs in data warehouse audit logs.
- Monitor for customer reports of unexpected app notifications as a potential early indicator of backend compromise, not just a UX glitch.
- Have an incident playbook ready for revoking and rotating API keys/tokens used by notification services (e.g., Firebase, OneSignal, or custom push infrastructure).
Developing story
This is a fresh, net-new disclosure with limited technical detail published so far — no CVE is associated with this incident, and attribution/scope remain unconfirmed beyond ASOS's acknowledgment. We'll track for updates. Read the original report at BleepingComputer.