Full Breakdown
ASOS Push-Notification Extortion Claim Triggers Market Turmoil
By Drooid · · How we work
The Incident on October 6, 2026
On Tuesday, October 6, 2026, thousands of users of the ASOS mobile app received a pop-up titled “ASOS HACKED.” The alert, addressed to the retailer’s data-protection officer and IT team, included a link to a newly created Telegram channel identified as the “Xuanye group gateway.” Users reported the notification on social media within minutes, and Downdetector logged roughly 500 reports of app issues just before 10 a.m. UK time, although services remained operational.
Background & Context
ASOS has faced prior cyber-security challenges. A credential-stuffing attack on July 28, 2026 compromised the accounts of 138,828 customers, with public notice issued on August 21, 2026. The October event follows a pattern of attacks on UK retailers, including recent breaches at Marks & Spencer, the Co-op and Harrods.
Timeline
- July 28, 2026 – Account-takeover attack affecting 138,828 customers.
- August 21, 2026 – ASOS disclosed the July breach.
- October 6, 2026 – Push-notification extortion message sent; ASOS acknowledges awareness.
Data & Statistics
- ASOS serves ?17 million customers in >150 countries.
- Downdetector recorded ?500 user-reported issues shortly before the notification.
- Shares fell as much as 13.2 %, narrowing to a ?9 % decline on the day of the incident.
- The Telegram channel linked in the alert was created the same day.
Official Statements & Responses
A company spokesperson confirmed that ASOS is aware of the reports but offered no details on whether the Snowflake environment was compromised or on the scope of any data loss. No formal breach notification has been filed with the UK Information Commissioner’s Office, as required for high-risk incidents.
Expert Assessment
Analysts highlighted the novelty of delivering an extortion demand through a consumer-facing app. The direct address to the DPO suggests attackers aim to trigger the statutory breach-notification clock. Use of a Telegram channel aligns with tactics seen in recent ransomware campaigns.
Conflicting Reports & Gaps
- Snowflake usage: Sources differ on whether ASOS actually employs Snowflake for data storage; the retailer has not confirmed its use.
- Extent of compromise: No evidence has been presented that data has been exfiltrated or leaked, and attackers have not released sample material.
- Notification pathway: Push-notification services are typically separate from data-warehouse platforms, leaving open how the attackers accessed the app’s messaging system.
Verbatim Quotes
- “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS's own app into their ransom note,” — Charlotte Wilson, head of enterprise at Check Point
- “What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.” — Marijus Briedis, CTO at NordVPN
What’s Next
UK data-protection law requires organisations to notify the Information Commissioner’s Office within 72 hours of becoming aware of a high-risk breach. ASOS has not indicated whether it will meet that deadline, and no further corporate communications have been released. Security firms caution that the public extortion note may invite follow-up phishing attempts targeting ASOS customers.
