Asos has launched an investigation into unauthorised access to its app notification systems, which may have exposed customer data.
The UK-based online fashion retailer said that an unidentified third party may have obtained basic personal information, including customer names and contact details. The company stated it did not believe that payment card records or passwords had been compromised. The disclosure followed a push notification titled 'Asos hacked', which reached thousands of app users and directed them to a channel on the messaging service Telegram.
Asos described the incident as unauthorised activity involving third-party platforms it uses to communicate with customers. The company restricted access to the notification platforms and is working with internal and external specialist advisers, as well as the relevant authorities. The retailer stated that its website and app continued to work normally, with no disruption to its operations. It later apologised to customers, asking them to disregard the message and not engage with the external link it contained.
Snowflake instance named in the message
The notification was addressed to Asos's data protection officer and IT team. It claimed that the sender had 'fully compromised the Snowflake instance'. Snowflake is a cloud platform used to store, process, and analyse data, including transactions and demographic information such as clothing sizes and body measurements. It also enables push notifications to mobile devices.
The Telegram channel appears to be run by a group calling itself the Xuanye Group, which told customers that payment information had not been affected and that the app was safe to use. A further post said the customer information was held on the group's server and would not be touched for a 'designated period', which indicates that Asos had been set with some form of deadline. According to Sophos, the fraudulent group had not previously been mentioned on hacker forums or other Telegram channels.
Market reaction and expert assessment
Asos shares fell by more than 14% on the London Stock Exchange after the notification circulated. They closed 9.56% lower after the company disclosed that it holds cybersecurity insurance, including business continuity cover, with a global provider. Asos added that it was too early to quantify any potential impact on trading.
The National Cyber Security Centre (NCSC), part of GCHQ, is offering assistance to the retailer. Dr Richard Horne, chief executive of the NCSC, said the incident illustrates how cyber incidents affect individuals more widely, not only the businesses targeted.
Security specialists pointed to the risk of follow-on fraud. Dray Agha, senior manager of security operations at Huntress, noted that sending a ransom demand directly to user devices is an aggressive extortion tactic intended to push the business into a quick negotiation. Agha advised shoppers to watch for targeted phishing while official confirmation of a data breach is pending.
Marijus Briedis, chief technology officer at NordVPN, warned that criminals may exploit the publicity with emails and texts impersonating Asos. These could ask customers to reset a password, confirm payment details, check an order, or claim a refund.
The incident follows a series of cyber incidents affecting UK retailers in 2025, including Marks & Spencer, the Co-op, and Harrods. M&S and the Co-op both experienced stock shortages, and M&S closed its website for several weeks while it worked to ensure its systems were clean.