ASOS Plc
Incident posture
Timeline
Summary
ASOS Plc confirmed it is investigating a suspected cyberattack after users of its shopping app received a notification threatening to leak data. The attacker claimed access to the company's Snowflake system and obtained names and contact details, saying payment card data was not compromised. Shares fell sharply, reflecting market concern. The Xuanye group used the retailer's push‑notification service to send extortion messages via Telegram. Snowflake said its platform showed no compromise, and the company noted it has cyber‑security insurance.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
ASOS Plc confirmed on October 6, 2026 that it is investigating a suspected cyberattack after users of its shopping app received a push notification threatening to leak data. The notification was sent at approximately 10 a.m. on Tuesday, October 5, 2026. ASOS stated that personal data including names and contact details may have been accessed in the attack. The company said it did not believe payment card information or passwords were accessed. ASOS described the incident as involving a breach of third‑party communication platforms used by the retailer. The retailer noted that it had 16.4 million active customers in more than 100 markets as of the end of its 2026 fiscal year.
The push notification claimed that the attackers had compromised ASOS’s Snowflake instance, a cloud‑based platform used to store large repositories of data, and included a link to a Telegram chat. The message addressed the company’s data protection officer and IT team, stating “Dear Asos DPO and IT, we have fully compromised the Snowflake instance, engage with us, or we will leak it.” The attackers identified themselves as the Xuanye group in posts on the Telegram platform. They asserted that payment information was not affected but claimed they had accessed customer data, without providing evidence. Bloomberg could not independently verify the claim of data access. A spokesperson for Snowflake Inc. said its investigation found no compromise of the Snowflake platform. Snowflake’s shares were little changed in trading after an earlier premarket drop in New York.
ASOS’s shares fell as much as 15% intraday in London, the largest intraday drop since May 2023, before the loss was partially pared. The retailer said it was too early to assess any impact on trading and noted that it has cyber security insurance. Little is known about the Xuanye group; it had not previously been linked to any cyberattacks or data breaches and appears to have created its Telegram channel specifically to promote the claimed compromise of ASOS. Avi Dayan, vice president of incident response at Sygnia Consulting, described the hijacking of ASOS’s notification system as a significant evolution in extortion tactics. The article also notes that, according to a UK government survey, about four in ten British businesses experienced a cybersecurity breach or attack in the past year, with medium and large firms being more likely targets. Jaguar Land Rover experienced a major cyberattack the previous year that led to factory shutdowns worldwide.
Sources
Sources available to members: 2 sources.