On 6 October 2026, ASOS customers received an unauthorised push notification claiming the retailer had been hacked. As investigations continue, the incident highlights the importance of managing third-party cyber risk across your digital ecosystem.
The incident is a timely reminder that cyber risk extends beyond an organisation’s own systems. Suppliers, logistics partners, cloud platforms and software providers can all introduce potential vulnerabilities, making it essential for businesses to understand where their data sits, who has access to it and how effectively third-party risk is being managed.
While this incident involved a retailer, vulnerabilities across suppliers, logistics partners and software providers can create risks throughout the wider digital ecosystem. If your business stores customer data in the cloud or communicates with customers through an app, now is the right time to take a closer look at your security posture.
What happened
ASOS app users opened their phones to find a push notification from the ASOS app titled “ASOS HACKED”. Although it went to customers, it was addressed to the retailer's data protection officer and IT team. It claimed the senders had “fully compromised the Snowflake instance” and threatened to leak data unless ASOS engaged with them.
The message linked to a Telegram channel set up the same day, which directed visitors to a channel run by a previously unknown group calling itself the Xuanye Group. The group has since claimed that payment information was not affected and that it holds customer information, but it has published nothing to support this.
ASOS has confirmed that the notification was unauthorised. It says it is investigating unauthorised activity involving third-party platforms it uses to communicate with customers. It has restricted access to those notification platforms and is working with specialist advisers and the relevant authorities.
According to ASOS, basic personal information, including names and contact details, may have been accessed. It does not believe payment card details or account passwords were affected, and its website and app are operating as normal. The National Cyber Security Centre is supporting the response. It advises ASOS customers to assume they are affected, even if they did not receive the notification.
ASOS has not confirmed whether a Snowflake environment was involved. Snowflake says it has found no compromise of its platform. The name will still be familiar to many. In 2024, a criminal campaign used login details stolen by malware to access organisations' Snowflake accounts that were not protected by multi-factor authentication (MFA). Ticketmaster and Santander were among those affected, and around 165 organisations were notified that they might have been exposed. Snowflake's own platform was not found to have been breached.
Managing your third-party cyber risk
Most organisations now rely on a wide network of suppliers, cloud platforms and service providers. We recommend starting with these steps to evaluate your third-party providers:
- Know where your data resides: Build and maintain an inventory of every third party that stores, processes or can access your data, including marketing, CRM and customer messaging platforms. Rank them by the sensitivity of the data they hold.
- Review access regularly: Remove dormant accounts, rotate shared credentials and API keys, and limit each supplier's access to what they genuinely need. Remove the access of lapsed suppliers that are no longer in use.
- Have a robust incident response plan in place: Make sure your incident response plan covers supplier breaches as well as incidents within your own organisation. Set out clear roles and escalation routes, how you'll contain any shared access, how you'll communicate with customers and partners, and how you'll guard against follow-on fraud. Then test it regularly, so everyone knows what to do.
- Check suppliers' security controls: Questionnaires are a starting point, but ask for evidence that key controls are in place and working. These include enforced MFA on all administrative and API access, regular penetration testing and timely patching.
The full picture will emerge as ASOS completes its investigation. The lesson, however, is already clear: resilience is only as strong as the weakest link in your digital ecosystem.
