Full Breakdown
ASOS Push-Notification Extortion Attempt Triggers Market Turmoil
By Drooid · · How we work
The Extortion Notification (Core Event)
On October 6, 2026, thousands of users of the ASOS mobile app received a pop-up titled “ASOS HACKED”. The message, addressed to the retailer’s data protection officer and IT team, read:
A link in the notification directed users to a newly created Telegram channel identified as the “Xuanye gateway”. The notification appeared to be sent through ASOS’s own push-notification system, suggesting attackers had gained access to that channel.
Background & Context
The incident follows a series of cyber-attacks on major British retailers, including Marks & Spencer, the Co-op and Harrods over the past two years. Those breaches have heightened scrutiny of cloud-based data platforms such as Snowflake, which stores large volumes of customer information for retailers.
Data & Statistics
- ASOS serves roughly 17 million customers across 150 countries.
- The London Stock Exchange share price fell almost 10 % (Guardian) and more than 11 % after the notification was reported.
- DownDetector recorded about 500 site-access complaints just before 10 a.m. on the day of the incident.
Official Statements & Responses
An ASOS spokesperson confirmed the company was “aware of the reports” but declined to comment further. No formal confirmation of a data compromise has been issued.
Expert Analysis (Verbatim Quotes)
- “Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access,” — Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes.
- “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS's own app into their ransom note,” — Charlotte Wilson, head of enterprise at Check Point.
- “Snowflake is a massive cloud database where retailers typically store sensitive customer information – it is a real worry if cyber criminals have indeed accessed it as they claim,” — Dray Agha, senior manager of security operations at Huntress.
- “Sending a push notification to ASOS’s app users would require access to the company’s notification system, which is separate from the Snowflake data platform the attackers claim to have compromised,” — Dan Bird, cybersecurity expert.
Market Impact (Why It Matters)
The abrupt share-price decline erased roughly £70 million of market value in a single session, underscoring how quickly a cyber-extortion attempt can affect investor confidence. The episode also spotlights the vulnerability of notification infrastructures, which can be weaponized to pressure target organisations.
Conflicting Reports & Gaps
- Snowflake compromise: Some experts treat the claim as a serious risk, while Dan Bird emphasizes that the notification system is distinct from Snowflake, implying attackers may have accessed multiple components.
- Scope of data exposure: No evidence has been presented confirming what, if any, customer records were accessed or exfiltrated.
- Attribution: The hacker group identifies itself as “Xuanye”. Sophos notes the group has not appeared on known forums, leaving its capabilities and motives uncertain.
What’s Next (Regulatory & Operational Outlook)
Under UK data-protection law, a confirmed breach that poses a high risk to individuals must be reported to the Information Commissioner’s Office within 72 hours. ASOS will need to determine whether the Snowflake environment or the notification system was breached before any statutory notification is triggered. Analysts recommend immediate credential rotation, multi-factor authentication enforcement, and a thorough review of relevant logs. Law-enforcement and incident-response teams are expected to be engaged as the investigation proceeds.
