UK shoppers are getting a very strange welcome back into their ASOS apps. The UK fashion retailer has reportedly been hacked, and the notification isn’t a standard security alert. It’s a demand.
According to the BBC, customers in the UK are seeing pop-up messages inside the official ASOS app, apparently sent by hackers who took control of some part of ASOS’ IT systems. The messages aren’t subtle. One reads: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” That’s a screenshot posted by an X user on Tuesday.
The incident looks widespread. Posts on social media suggest dozens of people have received the same message. ASOS itself has not posted anything about the incident through its official channels. Mashable has contacted the company and will update this article when we hear back.
The Demand Inside the App
The message is aimed directly at ASOS’ data protection officer (DPO) and IT staff. It doesn’t mince words. The hackers claim full control of a Snowflake instance, which is a data storage system. They want engagement, and they warn that a leak is coming otherwise.
The demand is simple: talk, or data goes public. The hackers are making their position clear rather than hiding behind coded warnings.
What Snowflake Is
Snowflake is a data storage company. Whether ASOS actually uses it isn’t confirmed. The official Snowflake website doesn’t mention ASOS in its list of partners, which means the company could be running on other systems entirely. But the reference to a Snowflake instance suggests the hackers are working from somewhere inside ASOS’ infrastructure.
The fact that the hackers named the system is telling. They’re not hiding their position. They’re making it clear where they stand.
The Telegram Channel Behind the Link
The message comes with a link. Users shouldn’t click it. According to the report, the link leads to a Telegram channel operated by a group called the “Xuanye Group.” That group has used the channel to brag about hacking ASOS.
Bragging about a hack is common in these situations. It’s a way of showing off, of warning other targets that this group knows what it’s doing.
What ASOS Should Do Now
For now, ASOS app users should refrain from using the app. The company has not issued any public guidance on the matter. The link in the pop-up is dangerous. Clicking it could lead to further infection or information exposure.
If you must know what the link does, it opens a Telegram channel where the Xuanye Group is posting about the hack. That’s the extent of what’s known. ASOS has not commented publicly on the incident.
Open Questions
There are still open questions. Has ASOS confirmed the breach? Is the Snowflake instance actually compromised? Have any customer records been accessed?
None of that is answered yet. The company has not spoken publicly, and the hackers have not provided proof of their claims. The situation remains unresolved.
The Order of Events
The incident follows a familiar pattern:
- Hackers gain access to ASOS’ IT systems.
- They send pop-up messages to customers via the app.
- The messages demand engagement from ASOS’ DPO and IT staff.
- The hackers threaten to leak data if their demands aren’t met.
- The link in the message leads to a Telegram channel operated by the Xuanye Group.
Each step moves the situation closer to a public data release. The hackers are pushing ASOS toward a confrontation.
What Shoppers Should Do
ASOS app users should take the advice seriously. Refrain from using the app until ASOS confirms it is safe. The company has not done so yet.
The hackers have shown they can reach customers directly through the app. That means they could send more messages, or worse, in the future. Until ASOS speaks, the safest move is to put the app aside.
The hackers have made their position clear. They have the data, and they want to talk before they release it. Whether ASOS engages or fights back is the question everyone is waiting on.
For now, ASOS app users should stay off the app. The company has not confirmed when it will be safe again. The situation is still developing, and the hackers are still holding their position.
The next few days will tell the story. Until then, shoppers should keep their distance.
Here’s what the situation amounts to:
- Pop-up messages appearing inside the ASOS app
- A demand addressed directly to ASOS’ DPO and IT staff
- A reference to a Snowflake instance being compromised
- A link leading to a Telegram channel operated by the Xuanye Group
- No response from ASOS through its official channels
That list shows how far the hackers went to make their presence known. They didn’t hide behind generic warnings. They named the system they took over and named the company they’re targeting.
The situation is unresolved because ASOS has not commented. The hackers have not provided proof of their claims either. Without confirmation from either side, the only safe assumption is that the app should not be used.
The company has not said whether customer data was accessed or how long the hackers have had access. Those details matter, but they are not known yet. The hackers have named the system, but naming a system is not proof of access.
Until ASOS speaks, the safest course is the simplest one. Put the app aside. Don’t click the link. Wait for the company to confirm the situation is resolved.
The hackers have made their position clear. They have the data, and they want to talk before they release it. Whether ASOS engages or fights back is the question everyone is waiting on.
For now, ASOS app users should stay off the app. The company has not confirmed when it will be safe again. The situation is still developing, and the hackers are still holding their position.
The next few days will tell the story. Until then, shoppers should keep their distance.
Source material: “ASOS app users spammed by weird messages after reported hack,” Mashable.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

