Asos is investigating after push notifications sent from its mobile app to customers today claimed hackers had “completely compromised” the data platform used by the online fashion retailer and threatened to leak what they had obtained.
The sign read: “Dear ASOS DPO and IT, we are completely compromised on Snowflake. Get involved with us, or we will leak. The DPO refers to the data protection officer, and Snowflake appears to be a reference to the US cloud-based data platform by that name.
Asos said it is still investigating and has not determined the cause of the alert. No cyber attacks have been confirmed. The company’s website and apps remain accessible afterwards.
Shares in the FTSE 250 group fell as much as 14 per cent to 432p.
The news is linked to a Telegram channel called Xuanye Gateway, which is new and does not belong to any known hacker group. The group said payment information was not affected.
Marijus Briedis, chief technology officer at NordVPN, said: “These are rude and threatening messages. The attackers not only claimed to have breached ASOS, but generally told the company to get involved or they would leak what they said.”
He added: “If the claim is proven to be genuine, the critical question is what information was held there and whether it was accessed or downloaded. But at this stage, customers should not assume that their personal information or payments have been stolen, which has not yet been established.”
Alan Woodward, professor of cybersecurity at Surrey University, said that hackers “might … gain access to the database, which means, if I’m an Asos customer, I would assume that someone has access to my personal data.”
Woodward also said that if the attacker simply compromised the marketing or push notification system, the alert could be an attempt to force Asos to pay the ransom quickly. “Hackers know that a public message seen by millions of customers will damage brand reputation and stock price immediately, whether the data leak claims are true or not,” he said.
Charlotte Wilson, head of UK & Ireland at cybersecurity firm Check Point, said people should be “extremely suspicious of emails, texts or messages claiming their Asos account has been compromised, offering a refund or asking them to reset their password via a link”.
The National Cyber Security Center’s guidance on data breaches tells customers to contact affected organizations through their official websites or social media channels, and not to use links or contact details in any messages they send.
Snowflake became the subject of a hacking campaign in 2024, when customers including Ticketmaster and Santander had their data stolen. Hackers from the ShinyHunters group stole the usernames and passwords the company used to access the service, and Snowflake then introduced multi-factor authentication across all accounts.
If confirmed, the incident would follow attacks on Marks & Spencer and the Co-op last spring, and an attack on Jaguar Land Rover, which the Cyber Monitoring Center estimated cost £1.9bn.
The sign comes as Asos pursues a turnaround plan under chief executive José Antonio Ramos Calamonte. The stock is up about 53 percent year-to-date ahead of today’s fall.
In a recent trading update, the company said it expected adjusted earnings to top the midpoint of a guided range of £150m to £180m this year. Total active subscribers were 16.4 million, according to an update for the year to the end of August.
Mike Ashley’s Frasers Group is the largest shareholder in Asos, with an estimated 29 per cent interest.