Today·Emerging
Follow-up 3h ago4
91%
ASOS app users receive threatening ransom notification from hackers
ASOS app users received a threatening push notification claiming hackers had compromised the company's Snowflake data platform and demanding engagement or threatening data leaks. The message, attributed to a group called Xuanye Group, indicates attackers may have accessed multiple ASOS systems. The company has not yet responded.
Quick Facts
- Push notification sent to ASOS app users containing extortion message
- Message claims compromise of ASOS Snowflake instance
- Threat to leak data unless attackers engaged with
- Link to Telegram channel created by Xuanye Group included in notification
- ASOS share price dropped approximately 5 percent



ASOS app users across the UK received push notifications on Tuesday, 6 October, containing a message apparently sent by hackers demanding engagement or threatening to leak company data. The message, addressed to ASOS's data protection officer and IT team, stated: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The notification included a link to a Telegram channel created by a group calling itself Xuanye Group, which has no known history of previous cyber attacks.
The incident is considered particularly serious by cybersecurity experts because the attackers appear to have compromised multiple systems within ASOS. Sending a push notification to app users requires access to ASOS's notification infrastructure, which is separate from Snowflake—the cloud data platform mentioned in the ransom message. This suggests attackers obtained credentials granting access to more than one part of the company's systems. The notification was delivered to a large portion of ASOS's user base, though the exact number of affected users remains unclear.
ASOA's share price fell approximately 5 percent following the notification. The company did not immediately respond to media inquiries or post about the incident on its social media accounts. ASOS reports 17 million customers annually across more than 150 countries. UK law requires companies to report data breaches to regulators within three days and to notify affected individuals in cases of high-risk breaches. Cybersecurity experts have urged users not to click on links in the notification or follow the Telegram channel, and to reset passwords by visiting the ASOS website directly rather than through the app.
Topics
Why This Matters
ASOS users across the UK—including potentially millions from the company's 17 million annual customer base—received an extortion notification, signaling attackers obtained credentials to both Snowflake cloud storage and the company's push notification infrastructure (separate systems). UK law mandates breach notification to regulators within 3 days and to affected individuals if high-risk. ASOS share price fell ~5% immediately. Measurable next steps: regulatory reporting deadline, individual notification timeline, and investigation into scope of compromised systems and customer data exposure.
Timeline & Sources
Oct 6, 2026
WirePush notifications received by ASOS app users with extortion message
Oct 6, 2026
WireWebsite functionality issues begin appearing on DownDetector with 500+ reports
Oct 6, 2026
WireThe Independent publishes report on notifications
Oct 6, 2026
WireBBC publishes report; Xuanye Group identified as claiming responsibility via Telegram
Oct 6, 2026
WireASOS share price down approximately 5 percent since notification sent
Sources
- ASOS hacked latest: Bizarre, threatening notification sent to customersThe IndependentMediaOct 6, 2026
- ASOS users stunned after receiving chilling 'hack' notification appearing to threaten app ownersLADbibleMediaOct 6, 2026
- ASOS app users receive push notifications apparently sent by hackersbbc.co.ukMediaOct 6, 2026
- ASOS have been hacked and a threat was sent to customers: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance.”independent.co.ukMediaOct 6, 2026