Live
Previously.
News
A shopper browsing clothing in a bright retail store
(Photo: FashionGonerogue)
Tech · Cybersecurity

ASOS Confirms Hack After Customers Get “ASOS HACKED” Push Alert; Shares Tumble

Thousands of shoppers woke up Tuesday to a push notification announcing the retailer had been “fully compromised.” Hours later, ASOS confirmed the attack — and told everyone not to click the link.

The Short Version

Advertisement
Share

Imagine waking up, glancing at your phone, and seeing a push notification from your favorite clothing app. Title: “ASOS HACKED.” Body: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” That’s what thousands of ASOS app customers saw on Tuesday morning UK time, according to The Times — a ransom note, delivered not by email, not in the dark, but through the company’s own app, straight to its customers’ lock screens.

Let that sink in. Whoever did this didn’t just want ASOS’s attention. They wanted ASOS’s customers to watch them get it. The message even came with a link to a newly created Telegram channel — “Xuanye Gateway” — that, per The Times, matches no known hacking group. No familiar ransomware brand, no established crew taking credit. Just a brand-new name, a brazen notification blast, and a demand.

The audacity is the story

Security incidents usually follow a grim choreography: intrusion, discovery, quiet containment, a carefully worded disclosure weeks later. This one skipped the choreography. Pushing the announcement through the victim’s own notification infrastructure is both a flex and a pressure tactic — it tells the company’s security team that the attackers can reach their customers directly, and it tells the customers that the company has lost control of the one channel it uses to talk to them. It’s extortion with an audience.

And it worked, at least in the narrow sense: within hours, ASOS confirmed it had been hacked. The company said “basic personal information including name and contact details may have been accessed,” adding that payment-card information and account passwords are not believed to be impacted. It warned shoppers not to click the link in the rogue notification. Read that warning as what it is: an admission that the notification was real enough to be dangerous.

A hand holding a smartphone showing app notifications on screen
Thousands of ASOS customers received the rogue “ASOS HACKED” push notification directly on their lock screens Tuesday morning. Photo: How-To Geek

Two claims, one collision

Here’s where it gets genuinely murky. The attackers claim they “fully compromised the Snowflake instance” — Snowflake being the cloud data platform behind ASOS’s customer data. But Snowflake told The Sun it had “found no compromise of the Snowflake platform” at this time. Both statements can’t be describing the same thing in the same way. Either the attackers are exaggerating their access, or the compromise happened somewhere in the chain between Snowflake’s platform and ASOS’s data — a connector, a credential, a third-party integration — that neither company is describing yet.

That gap matters more than the headline. ASOS described the exposed data as “basic personal information including name and contact details” — which sounds contained until you think about what it enables: with 17 million customers globally and the UK — ASOS’s largest market at 49% of revenue, per PA — sitting squarely in the blast radius, a list of names, emails, and phone numbers is a phishing operation waiting to happen. The notification link was the first attempt. It will not be the last.

Then there’s the mystery at the center of it: “Xuanye Gateway.” Established hacking crews have brands — they want the credit. A brand-new Telegram channel with no track record and no known group behind it suggests either a new player announcing itself or an established one wearing a mask. Either way, The Times reports the name matches nothing in the security community’s records — which means nobody knows who to negotiate with, or who to watch next.

The market did the math instantly

ASOS shares fell by as much as 14% to 432p, The Times reported, with other outlets putting the drop at 10–12%. The Register also covered the slide. A double-digit single-day drop for a breach involving “basic” personal data tells you what investors are pricing in: not the incident as described, but the incident as it might grow — regulatory scrutiny, customer churn, and the sheer reputational cost of having your ransom note delivered by your own app.

The UK’s National Cyber Security Centre — part of GCHQ — has offered ASOS assistance, PA reported. That’s not a casual courtesy call. When the government’s cyber arm gets involved, it signals that the incident is being treated as nationally significant, or at least as something that could become so. It also tends to mean the investigation is about to get very thorough, very quickly.

A customer shopping for clothes in a modern retail store
ASOS has around 17 million customers globally; the UK accounts for 49% of revenue — and this is the company’s second cyber incident in months. Photo: Yoobic

The pattern nobody wants to see

This is the second ASOS cyber incident in months. A July incident affected roughly 138,000 customers, according to classichits.ie. Two breaches in three months is not a coincidence — it’s a pattern, and patterns are what make customers leave. The first incident can be written off as bad luck. The second, announced via push notification to your customers’ phones, starts to look like a security posture problem.

For shoppers, the guidance is the unglamorous kind: don’t click the link in the rogue notification (ASOS said so itself), and treat any “ASOS” email, text, or call arriving in the next few weeks with deep suspicion — especially any of them asking you to confirm payment details or reset a password. The attackers have names and contact details. The next move is impersonation. If this week has a theme in tech security, it’s that the front door is getting harder to break down — our report on WhatsApp’s new restricted-chat privacy push — while the side doors keep swinging open.

Share this story