International Edition
Latest News
Business

ASOS customers receive threatening app alerts in suspected security breach

Fast fashion retailer ASOS suffered a suspected security breach on Tuesday, October 6, 2026, when hackers hijacked the company’s mobile app to send threatening push notifications to customers in Australia, the UK, and other parts of the world.…

Horoscope icon

Fast fashion retailer ASOS suffered a suspected security breach on Tuesday, October 6, 2026, when hackers hijacked the company’s mobile app to send threatening push notifications to customers in Australia, the UK, and other parts of the world. The alert, sent at about 8pm AEST, turned the retailer’s own application into a ransom note directed at the company’s data protection officer and IT department.

Screenshots shared by users showed an alert with the headline ASOS hacked, followed by the message: Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it. The notification included a link to a newly created channel on the messaging app Telegram, labelled as the Xuanye group gateway. While the website appeared to continue working as usual with no pop-ups, the incident sent ASOS shares plunging by up to 12.5 per cent on the London Stock Exchange.

App Control and Extortion Tactics

Cybersecurity specialists weighed in on the brazen nature of the attack, noting that the incident appeared to involve multiple systems. Dray Agha, senior manager of security operations at Huntress, told The Guardian that the push notification indicated attackers had breached the systems controlling the mobile app alongside the Snowflake cloud platform. Charlotte Wilson, head of enterprise at Check Point, told the BBC that sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force a quick negotiation. Dan Bird from Horizon3 noted that if both claims hold up, it suggests the attackers obtained credentials that opened more than one door.

ASOS customers receive shock hack notification

ASOS Investigates Potential Data Breach

ASOS has not made any announcements to customers regarding the message and did not immediately respond to requests for comment. It remains understood that the company is still investigating whether a data breach has actually taken place. Under UK law, companies are required to report personal data breaches to the Information Commissioner’s Office within 72 hours after discovering a breach. It is still not known how many customers were affected, whether ASOS is a customer of Snowflake, or what data, if any, is stored with the service.

About the author: Marcus Liu - Business Editor

MBA and ex‑B bureau chief specializing in global finance and fintech. Marcus speaks Mandarin, Japanese, and English, and has interviewed CEOs from the Fortune 50 to Y‑Combinator unicorns. Marcus Liu delivers sharp analysis on markets, startups, and corporate strategy for investors and entrepreneurs alike.