← Back to the feed

Asos investigates app message threatening to expose customer data

Developing story first seen 13 hours ago

Daily Mail ·

The hackers have given Asos a two-week deadline to pay ransom, with cyber-security experts describing the approach as "unusually brazen" and designed to whip up panic. Messages on the hackers' Telegram channel claim customer information is safe and "will not be touched for a designated period", suggesting this is an extortion attempt. Asos has confirmed unauthorised activity affected third-party communication platforms, potentially exposing customers' basic personal information including names and contact details, though payment card data and passwords appear unaffected.

The attack occurred at around 10am when customers received an unauthorised push notification claiming a "full compromise" of Asos's Snowflake cloud instance, with the message directing them to a newly created Telegram channel called Xuanye Group. Asos's website and app remain operational with no disruption to operations, and Snowflake has confirmed it found no compromise of its own platform. The retailer, which has 17 million customers across 150 countries, is investigating with specialist advisers and all relevant authorities, and has cyber security insurance. An update will be provided if the situation changes.

  • Hackers demand ransom from Asos with two-week deadline to avoid data leak.
  • Basic customer info exposed; payment details and passwords unaffected.
  • Snowflake platform not compromised; website and app operating normally.

New here? Start with this

Asos is one of the UK's largest online fashion retailers, selling to approximately 17 million customers across 150 countries. It is a major presence in British retail, making any security problem significant for a large number of shoppers.

Asos customers received a message through the retailer's mobile app claiming that someone had hacked into the company's systems and stolen customer information. It demanded that the company contact them through Telegram, threatening to publicly release the data if they did not comply.

Data breaches at large retailers can expose sensitive personal information including names, addresses and payment details, which criminals can use to commit fraud or theft. Such incidents also damage business confidence, as evidenced by Asos's share price falling 11 per cent following reports of the breach.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

The message appearing directly through Asos's own app or notification system indicates genuine system compromise rather than mere extortion bluff. The attacker's specific knowledge of Asos's Snowflake database configuration demonstrates technical access to the company's infrastructure, and with 17 million customers' payment and personal data at stake, this represents the exact profile of breaches that have cost corporations hundreds of millions. The threat must be taken seriously given that the attacker has demonstrably reached customers through official channels.

The case against

Mass extortion threats claiming database breaches are extremely common in cybercrime, typically from actors who simply purchased stolen data on the dark web or used basic social engineering. Genuine sophisticated attackers who compromise systems typically sell data quietly rather than announce themselves and demand contact via Telegram, immediately alerting the company and law enforcement to their presence. The fact that Asos's systems continued functioning normally and the attacker provided no actual proof of data theft suggests this is textbook extortion designed to panic the company into paying, rather than evidence of a real breach.

More coverage

Cybersecurity Technology World

Read the full article at the source →

Originally published by Daily Mail as “Asos is ‘hacked’ after customers receive message threatening to leak their data”.