JournalArta
Tuesday, October 6, 2026 · JakartaS&P 7,829.51 ▲0.71%USD/IDR 17,905 ▼0.02%Subscribe
JournalArta
Global Edition
beyond headlines
Advertisement
Technology · Apps & Software

ASOS Probes Threatening App Alert as Shares Fall Nearly 10%

ASOS is investigating a threatening notification sent to app users that claimed hackers had compromised a Snowflake database and threatened to leak data. The…

By matthew jonathan
October 6, 20263 min read
ASOS Probes Threatening App Alert as Shares Fall Nearly 10%
ASOS Probes Threatening App Alert as Shares Fall Nearly 10%. (AI Illustration)

ASOS is investigating a threatening notification sent to customers through its mobile app, after the message claimed the online retailer’s data had been compromised. The alert linked users to a Telegram channel, while the company’s website and app remained online on Tuesday morning.

The notification prompted concern among customers and coincided with a sharp fall in ASOS shares. The stock dropped almost 10% on the London Stock Exchange after thousands of customers received the message, according to The Guardian.

The alert was titled “Asos hacked” and addressed the company’s data protection and IT teams. It claimed attackers had compromised a Snowflake instance and threatened to leak data unless ASOS engaged with them.

ASOS was still investigating whether a hack had taken place, The Guardian reported. The company had not publicly commented on the notification in a separate report by Yahoo News.

Advertisement

The distinction matters: the message made a claim, but the available reporting did not confirm that customer data had been accessed or stolen. ASOS’s online services appeared to be functioning as the investigation continued.

Why the Snowflake claim matters

Snowflake is a cloud platform used to store, process and analyse information. The Guardian reported that retailers use it for data that can include transactions and demographic details such as clothing sizes and body measurements. The platform can also support push notifications to customers’ phones.

Dray Agha, senior manager of security operations at online security firm Huntress, said the claim would be serious if criminals had accessed the database. He also said the notification suggested attackers may have breached systems controlling ASOS’s mobile app.

That remains an assessment, not confirmation of a breach. A notification appearing in an app can raise questions about the systems behind it, but ASOS’s investigation had not established whether the hackers’ claims were true.

The link in the alert led to a Telegram channel operated by a group calling itself Xuanye. Cybersecurity experts told The Guardian they had not encountered the group before, and the report said it had not previously appeared on hacker forums or other Telegram channels.

Advertisement

New names do emerge in cybercrime, said Aiden Sinnot, principal threat researcher at Sophos. He said groups may wait for what they consider a significant opportunity before announcing themselves to build credibility.

Unverified claims can still create immediate risks. Marijus Briedis, chief technology officer at NordVPN, warned that criminals could exploit attention around the incident by sending emails or texts that appear to come from ASOS. Such messages might ask customers to reset passwords, confirm payment details, check an order or claim a refund.

Customers should treat unexpected requests for account or payment information with caution, particularly if they arrive through links in messages. Briedis said high-profile cyber incidents create favorable conditions for phishing attacks.

The episode comes after cyber incidents affected British retailers Marks & Spencer, the Co-op and Harrods last year, according to The Guardian. M&S and the Co-op experienced stock shortages, while M&S closed its website for several weeks as it worked to ensure its systems were clean.

For ASOS customers, the key unresolved issue is whether any data was accessed. The company was still investigating when its website and app remained online on Tuesday morning.

Source: theguardian.com

Advertisement
Advertisement