ASOS shares fell around 10% after hackers sent an unauthorised notification to customers and the retailer confirmed names and contact information may have been accessed.

ASOS Shares Fall After Cyber Incident Exposes Customer Data and Hackers Send Push Notification

The420 Web Correspondent
8 Min Read

Shares in British online fashion retailer ASOS fell sharply on Tuesday after hackers gained unauthorised access to third-party platforms used by the company to communicate with customers and sent a message directly to shoppers through the retailer’s notification system.

ASOS later confirmed that basic personal information, including customer names and contact details, may have been accessed.

The company said it does not believe payment-card information or account passwords were affected. Its website and mobile app continued operating normally.

ASOS shares closed about 9.6% lower after falling more sharply during trading as investors reacted to the incident.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Hackers Sent Message Directly to ASOS Customers

The incident became visible at around 10 am on October 6 when ASOS customers received an unauthorised push notification.

The message claimed that hackers had compromised an ASOS data environment and demanded that the company engage with them or face the release of stolen information.

The unusual tactic effectively turned ASOS’s own customer-communication infrastructure into part of the extortion attempt.

ASOS confirmed that the notification was unauthorised and said it immediately restricted access to the affected third-party notification platforms.

The company is working with internal and external cybersecurity specialists and relevant authorities.

Group Calling Itself Xuanye Claims Responsibility

A hacking group calling itself the Xuanye Group claimed responsibility for the attack.

The group said in the notification that it had “fully compromised” ASOS’s Snowflake environment and included a link directing users toward a Telegram channel.

In messages reviewed by Reuters, the group claimed it possessed customer information and threatened to release it unless ASOS engaged with the attackers.

The hackers themselves said payment information was not affected and that the ASOS app remained safe to use.

Those claims have not been independently verified.

ASOS has not confirmed that its Snowflake environment was compromised.

Snowflake Says Its Platform Was Not Breached

Snowflake, which provides cloud-based data storage and analytics services to thousands of organisations, launched an investigation after learning of the attackers’ claim.

The company said it had found no evidence that the Snowflake platform itself had been compromised.

That distinction is important.

A company using Snowflake can still potentially suffer compromise through stolen credentials, improperly secured integrations or another connected service without attackers exploiting a vulnerability in Snowflake’s core infrastructure.

Investigators have not yet publicly explained precisely how the ASOS incident occurred.

Names and Contact Details May Have Been Accessed

ASOS has so far confirmed only a limited category of potentially exposed information.

“Basic personal information including name and contact details may have been accessed,” the company said in its market announcement.

It added that it does not believe payment-card information or account passwords were compromised.

The retailer has not disclosed how many customers may be affected.

ASOS has around 16.5 million active customers across more than 100 markets.

It is therefore too early to determine the scale of the exposure.

Why Names and Contact Details Still Matter

A breach does not need to expose bank-card numbers to create a serious fraud risk.

Names, email addresses and phone numbers can help criminals create convincing phishing messages that appear to come from ASOS, delivery companies or payment providers.

Customers could receive fake refund notices, parcel-delivery messages or account-security warnings designed to steal passwords or banking credentials.

The fact that the attackers were able to send a genuine-looking notification through ASOS-linked infrastructure may make follow-on scams particularly convincing.

Customers should therefore be cautious about messages referring to the incident or asking them to verify their accounts.

ASOS Website and App Continue Operating

Unlike some major retail cyberattacks that have disrupted payments, warehouses or online ordering, ASOS said there was currently no operational disruption.

Its website and app remained available and functioning normally.

The company also said it carries cybersecurity insurance with a large global provider, including business-continuity coverage.

However, ASOS said it was too early to calculate any potential impact on trading.

Shares Fell Around 10%

The incident immediately affected investor confidence.

ASOS shares dropped more than 11% during trading before recovering some of those losses.

They eventually closed around 9.56% lower.

The fall came despite a strong year for ASOS shares, which had risen more than 60% in 2026 before Tuesday’s decline.

The retailer has been restructuring its business, selling assets and attempting to improve profitability after several difficult years in the highly competitive fast-fashion market.

Attackers Used an Unusually Public Extortion Method

One of the most notable features of the incident is how the attackers communicated their demand.

Cybercriminals traditionally contact companies privately after stealing information, often through email, dark-web portals or encrypted messaging services.

In this case, the attackers allegedly used ASOS’s own notification infrastructure to send their message directly to customers.

That can increase pressure on the victim company by making the security incident immediately public.

It can also cause reputational damage before investigators have established what was actually accessed.

Cybersecurity experts quoted in early reports described the tactic as an aggressive form of extortion designed to force the company into rapid negotiations.

Snowflake Has Been Targeted Before

The attackers’ reference to Snowflake has also drawn attention because customer environments hosted on the platform have been targeted in previous cyber campaigns.

In 2024, Google-owned cybersecurity firm Mandiant investigated attacks affecting data stored by at least 165 Snowflake customers.

Those incidents were linked largely to compromised customer credentials rather than a vulnerability in Snowflake itself.

Major companies affected during that earlier campaign included firms whose datasets had been stored within customer-controlled Snowflake environments.

There is currently no evidence that the same actors or methods were responsible for the ASOS incident.

Investigation Still at Early Stage

Several key questions remain unanswered.

ASOS has not disclosed how the attackers accessed the customer-notification systems, how many people had data exposed or whether information was actually copied from other company databases.

It has also not confirmed the hackers’ claim about Snowflake.

Snowflake has specifically said its investigation found no compromise of the platform itself.

ASOS said it will provide another update if the situation materially changes.

What this means for you

ASOS customers should be particularly cautious about emails, SMS messages or notifications asking them to reset passwords, confirm payment details or claim refunds following the incident. Access ASOS directly through its official app or website rather than through links sent in unexpected messages.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected