Skip to content
E-Tailing

Asos Shares Fall 10% After Hackers Hijack App to Send Extortion Alerts

By Sarah Chen
2 min read
ASOS1
ASOS1
In this article (9)

Shares in Asos dropped 10 per cent after hackers hijacked the retailer’s mobile notification network to deliver an extortion demand directly to shoppers’ phones.

Global markets including Australia, Ireland, France and Sweden received the alert on Tuesday. Shares tumbled as low as 432 pence in London trade.

The rogue push message hit customer devices around 10:00 BST. Addressed directly to the retailer’s data protection officer and technology teams, the notification read: “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It linked users to a Telegram channel run by a group calling itself Xuanye Group. In follow-up messages, the hackers claimed customer records were safe on their server and would not be touched for a set period. They also claimed payment data was untouched.

Breakdown of customer data exposure

Asos cut access to its third-party customer messaging systems once the broadcast went out. Core systems, the shopping app and regional websites continue to trade normally, management said. External forensic specialists are now investigating alongside regulators to determine the scope of the breach.

Basic personal records including names and contact details were exposed, the group confirmed. Payment-card details and passwords remained secure. Cloud storage provider Snowflake said its internal review found no compromise of its underlying platform.

“Engage with us, or we will leak it.” It linked users to a Telegram channel run by a group calling itself Xuanye Group.”

Ransom notes on customer screens

Hijacking a retailer’s push alert pipeline creates an operational headache for digital merchants across Asia-Pacific and Western markets. Intruders usually negotiate data ransoms behind closed doors. By weaponizing an app installed on over 10 million mobile devices, attackers force the victim into a public crisis before forensic teams can map the intrusion.

Vendor integrations create direct exposure for consumer brands using automated tools for customer alerts and data lakes. Here, the commercial risk is not system downtime. The storefront remains live. Instead, the danger lies in app uninstalls, consumer hesitation and friction at the digital checkout during peak shopping quarters.

Earlier data sprees and corporate recovery

Cyber gangs have targeted cloud repositories relentlessly over the past two years. Google subsidiary Mandiant tracked an intrusion campaign targeting Snowflake credentials across at least 165 corporate clients in 2024. British operators have also suffered hits, with Marks & Spencer, the Co-op and Jaguar Land Rover enduring major operational disruption from security breaches.

This breach hits Asos during a delicate corporate turnaround. Asset sales and an improved fiscal 2026 earnings forecast had lifted its share price by more than 60 per cent earlier this year. The group holds cyber insurance covering business continuity. Management noted it is too early to assess the financial impact on trading.

Investigation underway with regulators

Technical teams are now investigating how the payload bypassed internal controls on the notification platform. Asos has not disclosed how many of its 17 million active global customers received the message.

Attention now turns to whether the UK Information Commissioner’s Office receives a formal breach filing once forensic checks conclude. Investors will look to the next trading update to see if customer orders softened after the scare.

Questions & Answers

Q.

What kind of customer information was compromised in this security breach?

A.

Basic personal records including names and contact details were exposed. However, the group confirmed that payment-card details and passwords remained secure, and core systems continued to trade normally.

Q.

Which specific geographical markets received the extortion alert from the hackers?

A.

Global markets, including Australia, Ireland, France, and Sweden, received the alert. The message was delivered directly to shoppers' phones around 10:00 BST on Tuesday.

Q.

What is the primary commercial risk for Asos, given that its storefront remains operational?

A.

The main commercial risk is not system downtime, as the storefront is live. Instead, the danger lies in app uninstalls, consumer hesitation, and friction at the digital checkout during crucial shopping periods.

Q.

How did the Asos share price react immediately after the hacking incident became public?

A.

Shares in Asos dropped by 10 per cent immediately after the incident. In London trade, the share price tumbled as low as 432 pence following the public extortion demand.

Reader pulse

How will this affect Asos sales?

22,014 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready