Skip to content
6 October 2026

ASOS push alert claims data breach, shares tumble

A counterfeit ASOS push message claimed a full Snowflake breach, prompting a steep share drop and warnings of phishing scams.

ASOS push alert claims data breach, shares tumble

On Tuesday morning, 6 October, thousands of shoppers using the ASOS mobile application were confronted with a startling push notification. Titled “ASOS hacked”, the alert warned that the retailer’s data stored in a Snowflake instance had been “fully compromised” and included a link to a Telegram channel. The message also demanded that the company engage with the sender or face a public leak. Despite the alarm, the ASOS website and app continued to function, and the company has not confirmed whether any customer information was actually stolen.

Details of the suspicious notification

The notification read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The abbreviation DPO refers to the data protection officer, a role mandated by privacy regulations. Snowflake is a cloud-based data platform that many large retailers use to store transaction records, demographic details and even size measurements. Cyber-security expert Jake Moore, global cyber security adviser at ESET warned users not to click the Telegram link, calling the incident “one of the most visible hacks in history”.

Who may be behind the alert?

Analysis of the Telegram URL points to a group calling itself the Xuanye gang, a name that had not appeared on public hacker forums before. Aiden Sinnot, principal threat researcher at Sophos explained that new criminal collectives often wait for a high-profile target before announcing themselves, in order to gain credibility within the underground ecosystem. Dray Agha, senior manager of security operations at Huntress described the push as “clear public extortion”, emphasizing that sending a ransom demand directly to consumer devices is an “aggressive extortion tactic designed to force the business into a quick negotiation”.

Financial impact and market response

ASOS, which serves about 17 million customers across more than 150 countries each year, saw its shares tumble sharply after the alert spread. Initial estimates placed the plunge at roughly 10 to 12% on Tuesday morning, erasing around £70 million from the company’s market value. Some trading platforms later reported a decline exceeding 14% underscoring the volatility triggered by the perceived breach. The rapid price drop illustrates how a single cyber-related message can reverberate through the equity markets of a global retailer.

What users should watch for next

Security professionals caution that the immediate danger may shift from a direct data leak to a wave of phishing attacks. Marijus Briedis, chief technology officer at NordVPN advised customers to remain vigilant for unexpected emails or texts that appear to come from ASOS, especially messages that request password resets, payment verification or order confirmations. Such scams often exploit the publicity surrounding a breach to deceive unwary recipients. He emphasized that “high-profile cyber incidents create ideal conditions for phishing attacks”.

While the investigation continues, ASOS has not publicly confirmed any data exfiltration. The company’s statements remain limited, and the authenticity of the Telegram channel’s claims is still under scrutiny. Users are encouraged to avoid clicking unfamiliar links, monitor their financial accounts for unusual activity, and follow official communications from ASOS for any verified security updates.

Author

Jordan Wells

Jordan Wells covers Pride, policy and the cultural arc with equal seriousness. Reports on legislation, films, and the writers reshaping queer narrative today.