ASOS app push alert claims Snowflake hack, shares drop
Shares in ASOS, the British online fashion retailer, dropped by more than 10% on Tuesday after customers said they had received a push notification through the company's app claiming the business had been hacked.
The message pointed to a previously unknown extortion group and named the company's Snowflake environment as the target. No evidence of a breach has been made public so far.
A ransom note delivered through the official app
Customers posted screenshots of the alert on social media. The notification carried the title "ASOS HACKED" and read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
DPO refers to the data protection officer, the person responsible for overseeing how a company handles personal data. Snowflake is a cloud platform that companies use to store and analyze large volumes of data.
The notification included a link to a Telegram channel that calls itself Xuanye Group. Experts who track cyber extortion groups had not seen the name before. The approach is also unusual. Extortion groups normally contact a company privately first, and only later publish stolen data or publicly claim a breach.
Whoever sent the alert did not provide any proof that they had compromised ASOS's Snowflake environment.
What the Telegram channel says
The first post on the channel presented it as Xuanye Group's official broadcast outlet. It warned readers about impersonators and said a separate "gateway" channel would point users to a replacement if the main channel was taken down.
A later post stated: "Regarding ASOS, payment information is not affected."
The group did not back up that statement and did not say what data, if any, it had taken. The channel held no samples of customer records or any other material that would independently support the claims.
ASOS, which is listed on the London Stock Exchange, did not respond to a request for comment.
The notification is the only evidence
At this point, the only sign of a possible intrusion is the fact that the message arrived as an ASOS app notification. If that is confirmed, it would mean the sender had access to at least part of the company's customer-messaging infrastructure.
That does not automatically connect the alert to Snowflake. The platform can be linked to other business systems, but there is no public evidence that ASOS uses Snowflake to send push notifications. There is also no public evidence that Tuesday's alert came from the company's Snowflake environment.
In other words, two separate claims are bundled together: that someone controlled the app's messaging channel, and that someone stole data from a cloud data warehouse. Only the first is supported by anything visible to the public, and even that has not been confirmed by the company.
Investors reacted before the facts were known
Charlotte Wilson, an executive at cybersecurity company Check Point, said: "If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS's own app into their ransom note."
She also pointed to how fast the share price fell after the alert went out. According to Wilson, it showed that "before the company had even publicly established what had happened, investors were already pricing in the potential consequences."
The market reaction is notable because it came without leaked data, without a confirmed breach and without a statement from ASOS. A single message to customers' phones was enough to move the stock.
The Bigger Picture
This incident suggests that a company's own communication channels can become a powerful extortion tool. A ransom note that lands on customers' phones under the retailer's name puts public pressure on the business in a way a private email to the security team does not. Similar cases, such as the hijacked Microsoft X account used to promote a crypto token, or the compromised Nikkei account that sent thousands of phishing emails, show how much damage control of a trusted sender can cause, regardless of what else the attackers have access to.
For security teams, the lesson is that push notification services, marketing platforms and other customer-messaging tools deserve the same level of protection as databases and payment systems. Access to these tools is often spread across marketing staff, agencies and third-party providers, which can widen the attack surface. Strong authentication, tight permission scopes and alerting on unusual campaigns look like sensible priorities.
For customers, the advice is simple: treat unexpected messages with caution, even when they appear inside a legitimate app, and do not follow links to unknown channels.
The case also shows how unverified claims can have real financial effects. The share drop came before any evidence surfaced, which may encourage other groups to try the same tactic. It is worth watching whether ASOS confirms or rules out unauthorized access to its messaging systems, whether any data from a Snowflake environment appears, and whether Xuanye Group turns out to be a new actor or a rebrand of an existing one. Until then, the gap between what the group claims and what has been shown remains wide.
