Asos investigates app message threatening to expose customer data
Developing story first seen 13 hours ago
The hackers have given Asos a two-week deadline to pay ransom, with cyber-security experts describing the approach as "unusually brazen" and designed to whip up panic. Messages on the hackers' Telegram channel claim customer information is safe and "will not be touched for a designated period", suggesting this is an extortion attempt. Asos has confirmed unauthorised activity affected third-party communication platforms, potentially exposing customers' basic personal information including names and contact details, though payment card data and passwords appear unaffected.
The attack occurred at around 10am when customers received an unauthorised push notification claiming a "full compromise" of Asos's Snowflake cloud instance, with the message directing them to a newly created Telegram channel called Xuanye Group. Asos's website and app remain operational with no disruption to operations, and Snowflake has confirmed it found no compromise of its own platform. The retailer, which has 17 million customers across 150 countries, is investigating with specialist advisers and all relevant authorities, and has cyber security insurance. An update will be provided if the situation changes.
- Hackers demand ransom from Asos with two-week deadline to avoid data leak.
- Basic customer info exposed; payment details and passwords unaffected.
- Snowflake platform not compromised; website and app operating normally.
New here? Start with this
Asos is one of the UK's largest online fashion retailers, selling to approximately 17 million customers across 150 countries. It is a major presence in British retail, making any security problem significant for a large number of shoppers.
Asos customers received a message through the retailer's mobile app claiming that someone had hacked into the company's systems and stolen customer information. It demanded that the company contact them through Telegram, threatening to publicly release the data if they did not comply.
Data breaches at large retailers can expose sensitive personal information including names, addresses and payment details, which criminals can use to commit fraud or theft. Such incidents also damage business confidence, as evidenced by Asos's share price falling 11 per cent following reports of the breach.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
The message appearing directly through Asos's own app or notification system indicates genuine system compromise rather than mere extortion bluff. The attacker's specific knowledge of Asos's Snowflake database configuration demonstrates technical access to the company's infrastructure, and with 17 million customers' payment and personal data at stake, this represents the exact profile of breaches that have cost corporations hundreds of millions. The threat must be taken seriously given that the attacker has demonstrably reached customers through official channels.
The case against
Mass extortion threats claiming database breaches are extremely common in cybercrime, typically from actors who simply purchased stolen data on the dark web or used basic social engineering. Genuine sophisticated attackers who compromise systems typically sell data quietly rather than announce themselves and demand contact via Telegram, immediately alerting the company and law enforcement to their presence. The fact that Asos's systems continued functioning normally and the attacker provided no actual proof of data theft suggests this is textbook extortion designed to panic the company into paying, rather than evidence of a real breach.
Full account
Asos customers received an unexpected notification on the fashion retailer's mobile application this morning alerting them to a potential data breach. The message, titled 'Asos hacked,' directed users to a Telegram channel whilst demanding the company's data protection officer and IT department engage with those claiming responsibility for the intrusion. The alert was subsequently identified as unauthorised, prompting Asos to launch an investigation into what has become one of the most significant cybersecurity incidents affecting a major British retailer.
The company has confirmed that individuals behind the breach, who have identified themselves as the Xuanye group, may have obtained access to fundamental customer information such as names and contact details through what appears to be a compromise of Snowflake, a cloud-based platform Asos utilises for storing and analysing data. However, Asos has stressed that sensitive payment card information and account passwords appear to have remained secure. The retailer's platform continues to function normally, with no operational disruptions reported to either its website or mobile application since the unauthorised message was circulated.
The disclosure has triggered a marked reaction in financial markets, with shares in the online retailer initially declining sharply before recovering somewhat following Asos's announcement that it holds comprehensive cybersecurity insurance with a multinational provider. The company is working alongside law enforcement agencies and external security specialists, though executives cautioned that assessing the full commercial implications remains premature. The government's National Cyber Security Centre has offered its support to the investigation.
Security researchers have characterised the public notification sent to customers as an unusual confrontational approach, potentially designed to exert financial pressure on the company whilst simultaneously generating publicity. Specialists have advised customers to remain vigilant against follow-up phishing campaigns. The group claiming responsibility appears previously unknown within cybersecurity circles, prompting some commentators to suggest the incident may represent an opportunistic attempt to establish notoriety rather than a sophisticated, premeditated operation.
Where outlets differ
Source 1 emphasises the 'unusually brazen' psychological warfare element; Source 2 frames it as an aggressive extortion tactic designed to force quick negotiation
Source 2 provides specific share price movements (14% initial drop, 11% final); Source 1 mentions the impact but without numerical detail
Source 2 explicitly includes National Cyber Security Centre involvement; Source 1 does not reference this
Source 2 features Huntress security firm warning about targeted phishing risks; Source 1 discusses psychological warfare more broadly
Source 1 includes customer scale information (17 million across 150 countries); Source 2 omits this detail
Source 2 emphasises that Xuanye group appears previously unknown to security experts; Source 1 does not highlight this aspect
More coverage
- The Guardian — Asos customers receive ‘hack’ notification threatening to leak data
- Engadget — Asos hit by extortion hack that may have compromised some customer data
Cybersecurity Technology World
Read the full article at the source →
Originally published by Daily Mail as “Asos is ‘hacked’ after customers receive message threatening to leak their data”.