Asos App Hijacked for Public Extortion, Triggering 10% Share Drop

4 min read
Source: BBC
Asos App Hijacked for Public Extortion, Triggering 10% Share Drop
Photo: BBC
TL;DR

Asos confirmed that hackers sent an unauthorized notification to its app users, claiming to have compromised its Snowflake data instance. The message, which demanded engagement via a Telegram channel, caused a 10% drop in share value. The retailer states that basic personal information may have been accessed, but payment details and passwords remain secure. The National Cyber Security Centre is assisting with the investigation.

Key points

  • Asos acknowledged an 'unauthorised customer notification' sent to app users on Tuesday morning, which included a link to a Telegram channel.
  • The message, titled 'ASOS HACKED', claimed that the company's Snowflake data instance was fully compromised and demanded engagement or threatened to leak data.
  • Asos shares fell by approximately 10% on the London Stock Exchange following the incident, with some reports citing a 14% initial dip.
  • The company stated that 'basic personal information' such as names and contact details may have been accessed, but it does not believe payment card information or account passwords were compromised.
  • The National Cyber Security Centre (NCSC) has offered assistance to Asos, and the retailer has not yet reported the incident to the Information Commissioner's Office (ICO).
  • Cybersecurity experts described the attack as a 'brazen' extortion tactic, noting that sending ransom demands directly to consumer devices is rare and designed to apply public pressure.

Background

This incident follows a series of cyber attacks on major UK retailers in the previous year, including Marks & Spencer, the Co-op, and Harrods. Asos serves approximately 17 million customers across 150 markets. The attack targets Snowflake, a cloud platform used for data storage and analysis, which has been linked to previous high-profile breaches involving firms like Ticketmaster and Santander. The archive notes that while AI agents like Meta's Muse have raised concerns about data access, this incident involves a direct compromise of a third-party data platform rather than an AI-driven error.

How outlets are covering it

BBC and The Guardian both emphasize the 'brazen' nature of the attack, highlighting that hackers used the retailer's own app to send extortion demands to customers, a tactic described as rare. The Guardian notes that the hackers, identified as the 'Xuanye Group,' had not been previously mentioned on hacker forums, suggesting a new group entering the ecosystem with a high-profile target. News.com.au focuses on the financial impact, reporting a 12.5% share drop and a loss of approximately $133 million in value, while also noting that Asos's 2025 revenues had already declined from the previous year. All sources agree that Asos has not yet reported the breach to the ICO, though the NCSC is involved. The Guardian adds that Asos has cybersecurity insurance, which may mitigate financial impacts, a detail not mentioned in the BBC or News.com.au reports.

Why it matters

This incident marks a significant shift in cyber-attack tactics, where attackers use a company's own communication channels to pressure them publicly, rather than conducting extortions in private. It highlights the vulnerability of third-party platforms like Snowflake, which are central to modern data management. For consumers, it raises concerns about the security of personal data in the retail sector and the potential for follow-up phishing attacks. For the industry, it underscores the need for robust security measures and rapid response protocols to protect customer trust and financial stability.

What to watch

Asos is investigating the incident with internal and external specialists, and the NCSC is providing assistance. The company has urged customers not to engage with the notification and to change passwords if concerned. It is unclear how many customers received the notification, but the app has over 10 million downloads. Asos has not yet reported the breach to the ICO, and it is too early to quantify the full impact on trading. Customers are advised to watch for phishing attempts and to enable two-step verification on their accounts.

Share this article

Want the full story? Read the original reporting

Read on BBC