Shares in Asos dropped nearly 10% on the London Stock Exchange after the online fashion retailer was targeted by a sophisticated cyber incident involving its own customer communication channels. The company confirmed it is investigating unauthorised access to third-party platforms used to send push notifications to shoppers.
The disruption began when thousands of customers received a message titled “Asos hacked” on their mobile devices. The notification appeared to come directly from the retailer but contained a link that redirected users to a Telegram messaging channel. This channel was operated by a group calling itself the Xuanye Group, which claimed to have “fully compromised” Asos’s Snowflake data instance.
Asos share price impact and response
The immediate market reaction was sharp, with the company’s stock value diving more than 14% at one point during the trading day. By the close, shares had settled at a 9.56% decline. The volatility followed the release of a statement from Asos confirming the breach of its notification systems.
Asos clarified that the unauthorised activity involved platforms used to communicate with customers, rather than its core transactional infrastructure. The retailer stated it had taken immediate action to restrict access to the affected notification platforms. It also confirmed that it has cybersecurity insurance with a large global provider, which includes business continuity coverage.
“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers,” the company said in a statement. “We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
The retailer later issued an apology to customers, advising them to disregard the notification and not to click on any external links contained within it. Asos emphasised that its website and app were operating normally with no current disruption to its operations.
Data breach scope and Xuanye Group claims
While the Xuanye Group claimed to have accessed the Snowflake instance, Asos maintained that basic personal information, such as names and contact details, was the only data potentially at risk. The company explicitly stated that it did not believe payment card records or user passwords had been compromised.

Snowflake is a cloud platform that Asos uses to store and analyse data, including transactions and demographic information like clothing sizes and body measurements. The platform also facilitates the push notifications that were weaponised in this incident.
The Telegram channel operated by the Xuanye Group posted messages assuring customers that payment information was not affected. One post stated that the incident involved customer information held on their server and that it would not be touched for a designated period. The group also indicated that the app was safe to use, suggesting a potential deadline or negotiation tactic.
Cybersecurity experts noted that the Xuanye Group was previously unknown in hacker forums or other Telegram channels. Aiden Sinnott, a principal threat researcher at Sophos, suggested that new groups often wait for significant opportunities to announce themselves to gain credibility in the cybercriminal ecosystem.
Security warnings and industry context
The National Cyber Security Centre (NCSC), part of the UK’s GCHQ intelligence agency, is offering assistance to Asos. Dr Richard Horne, the NCSC chief executive, highlighted how such incidents affect individuals widely, not just large businesses.
Security firms have warned that the publicity surrounding the Asos hack notification could lead to a surge in phishing attempts. Dray Agha of Huntress advised shoppers to watch out for targeted phishing emails or texts claiming to be from Asos, asking for password resets or payment confirmations. Marijus Briedis of NordVPN echoed these concerns, noting that criminals often exploit high-profile cyber incidents to launch secondary attacks.
This incident follows a series of cyber challenges for major British retailers last year. Marks & Spencer, the Co-op, and Harrods all suffered cyber incidents that led to stock shortages and website closures. Asos is now working to restore full confidence in its systems while the investigation continues.
Source: The Guardian

