Blog / Ecommerce
The Ransom Note Came as a Push Notification
What the ASOS app hack tells every ecommerce team about where breaches really start, and the five questions to ask your own stack this week.
At around 10am on Monday, ASOS app users across the UK unlocked their phones to an ASOS notification headed "ASOS HACKED".
It wasn't a sale or a delivery update. It was a message addressed to ASOS's own data protection officer and IT team, claiming the attackers had taken over the company's Snowflake data platform and threatening to leak it unless ASOS engaged with them (Computer Weekly).
I've spent my career on the growth side of ecommerce: Shopify Plus builds, CRO, CRM, email and paid channels. This ASOS hack landed differently for me, because the attackers didn't break the checkout. They used the tools that people like me set up to talk to customers.
What's confirmed so far. ASOS says an unauthorised notification went out at around 10am, that it is investigating activity involving third-party platforms it uses to communicate with customers, and that names and contact details may have been accessed. It does not believe card details or passwords were affected. The Snowflake claim has not been confirmed. Details may change as the investigation goes on.
What happened
- 6 Oct, around 10:00. UK app users receive a push notification headed "ASOS HACKED" with a link to a Telegram channel.
- Who. BBC Verify linked the channel to a group calling itself Xuanye Group. Not a name with a track record.
- The claim. The group says it compromised ASOS's Snowflake instance, that card data was not taken, and that it will hold the data for a set period.
- 16:15 BST. ASOS confirms the notification and says it is investigating its third-party customer communication platforms (Forbes).
- Still open. How many customers are affected, exactly what was taken, and whether the Snowflake claim is true.
Security experts quoted by the BBC said using a company's own app to push a ransom demand to customers is almost unheard of (InternetRetailing). Whatever the final scope of the data theft, sending that message proves the attackers had working access to at least one system able to reach every app user.
The second ASOS incident in ten weeks
In late July, ASOS spotted attackers logging into US customer accounts with passwords stolen from other websites. Customers were forced to reset passwords, and the fraud team blocked or cancelled suspicious orders. A US law firm investigating the case puts the number affected at around 138,000 (eSecurity Planet).
Nothing links the two incidents publicly. Put them side by side, though, and they say the same thing. The storefront held up. The weak points were customer logins in July and customer messaging tools in October.
The checkout held. The growth stack didn't.
Why the growth stack is the new front door
Most retailers have done the hard work on payments. Card numbers are tokenised by Shopify, Stripe or Adyen, so even serious breaches rarely expose full card data. Attackers have adapted. They now go after the systems that hold customer profiles and the tools that can message every customer at once.
Those systems tend to have three things in common. Marketing or ecommerce teams buy and run them. They're wired to each other with API keys nobody reviews. And quite often a password is the only thing protecting them.
Snowflake is the clearest example. In 2024, attackers used logins stolen by malware from staff laptops to get into around 165 companies' Snowflake accounts, including Ticketmaster, AT&T and Advance Auto Parts. Snowflake's own platform wasn't hacked. The accounts simply had no multi-factor authentication. The main hacker pleaded guilty in August, and Snowflake is phasing out password-only logins entirely by this month (Rescana).
Same pattern, different door
M&S, April 2025. Attackers talked their way in by phone. M&S paused online clothing orders for seven weeks and estimated around £300m in lost operating profit before insurance and cost savings (Business Insurance).
TfL, September 2024. Two Scattered Spider members were jailed in July for an attack that took 148 internal systems offline, exposed Oyster refund data and cost around £29m to fix (The Record).
Harrods, September 2025. 430,000 online customers' details were taken from a supplier's system, including loyalty tier and co-branded card labels. Harrods' own systems weren't touched (The Register).
Kering, Chanel and Adidas, 2025. Staff were tricked into approving a fake app connected to Salesforce, which let attackers export customer records in bulk. For Kering's luxury brands, that included how much each customer had spent (TechCrunch).
None of these were exotic hacks. Every one came through a login without strong authentication, a person on the phone, a supplier, or a connected app.
Why this should matter to marketers
The data being stolen is marketing data. Names, emails, addresses, order history, loyalty tiers and spend levels. It's exactly what an attacker needs to send a phishing email that looks like it came from your brand. Every breach supplies the raw material for the next one, and your customers are the ones who pay for it.
The commercial cost is real too. Signifyd reported account takeover attacks up 78% year on year in early 2026 (CPA Practice Advisor). Akamai found 85% of commerce businesses had an API-related incident last year, yet only 22% know which APIs expose sensitive data (Akamai). In the UK, the Data (Use and Access) Act has raised fines for marketing rule breaches to UK GDPR levels and given the ICO wider investigation powers (Bevan Brittan).
And trust breaks faster than any campaign can rebuild it. A customer who gets "ASOS HACKED" from the ASOS app is going to hesitate before tapping the next notification, even a genuine one.
Five questions for your team this week
Take these into your next stand-up.
- Who has admin access to our email, SMS and push tools, and is MFA enforced for every one of them? Include agencies, freelancers and people who left last year. Check whether each tool lets you require MFA for the whole account, not just offer it.
- Which apps and API keys can message every customer at once? List every integration with send permissions. Remove what you don't use and rotate keys older than a year.
- Is our data warehouse locked to MFA and known networks? If you use Snowflake, BigQuery or Redshift, check service accounts as well as people. Snowflake is enforcing this for you this month whether you're ready or not.
- Would we get an alert for an unusual send or a bulk export? A campaign going to the full list at an odd hour, or a 500,000-row export, should page someone.
- Is the first-hour customer message already written? ASOS customers spent most of Monday asking each other what the notification meant. A pre-approved holding statement, ready for the app, email and social, saves the hours that matter most.
The takeaway
Security in ecommerce used to mean PCI compliance and a firewall. In 2026 it means the whole growth stack: customer logins, CRM, loyalty, email, push and the data warehouse behind them. Those tools belong to ecommerce and marketing teams, so more and more of the responsibility does too.
If you run ecommerce or CRM for a brand, you don't need to become a security engineer. You do need to know who can log into your tools, what they connect to, and what happens when one of them sends a message you didn't write.
I'll be writing more on auditing the growth stack. The breakdowns go up on Instagram first.