Security News

ASOS Shares Tumble After App Notification Claims Company Was Hacked

The Record · 6 Oct 2026
Key Takeaway Lock down the accounts and tools your business uses to message customers, with strong authentication and tight access controls, and have a plan ready for responding quickly if they are misused.

Shares in British online fashion retailer ASOS fell more than 10% on Tuesday after customers reported receiving a push notification through the company's app saying it had been hacked. Screenshots on social media showed a message addressed to the company's data protection and IT teams, claiming the sender had fully compromised its Snowflake cloud data environment and demanding contact, or the data would be leaked. The notification linked to a Telegram channel run by a group calling itself Xuanye Group, a name not previously seen by experts who track cyber extortion groups.

The claims remain unverified. The group provided no evidence that it had accessed ASOS's Snowflake environment, and its Telegram channel contained no samples of customer data. A later post said payment information was not affected, but again offered no proof. The only evidence of any compromise is that the message appeared as an ASOS app notification, which, if confirmed, would suggest the sender had access to at least part of the company's customer-messaging systems. There is no public evidence that ASOS uses Snowflake to send push notifications. ASOS did not respond to a request for comment.

Charlotte Wilson of Check Point called it a deeply serious attack if confirmed, noting the hackers appeared to have turned ASOS's own app into their ransom note. She said the share price fall showed investors were pricing in the consequences before the company had publicly established what happened.

ASOS data breach extortion push notifications Snowflake

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.