Shares in British clothing company ASOS dive after hackers apparently send push notification
ASOS shares fell over 10% after an unconfirmed app alert claimed hackers compromised its Snowflake data environment.
Shares in British online retailer ASOS fell more than 10% on Tuesday after customers received an app push notification titled "ASOS HACKED," claiming the company's Snowflake instance was fully compromised and demanding contact or a leak. The alert linked to a Telegram channel calling itself Xuanye Group, a name extortion trackers had not previously seen, which later said payment information was unaffected without providing evidence. No customer-data samples were posted, and there is no public evidence that ASOS uses Snowflake to send push notifications. ASOS did not comment; the only indication of access is that the message appeared inside the company's app.
- An ASOS app alert titled ASOS HACKED claimed a full Snowflake compromise.
- The linked Telegram channel, Xuanye Group, is previously unknown to extortion trackers.
- No stolen-data samples or proof of a Snowflake breach were published.
- ASOS shares fell more than 10% before the company confirmed anything.
Full article421 words · extracted from therecord.media · click to collapse
Shares in British online fashion retailer ASOS fell more than 10% on Tuesday after customers reported receiving a push notification through the company’s app saying the business had been hacked. Screenshots shared on social media showed a notification titled “ASOS HACKED” that said: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The notification linked to a Telegram channel calling itself Xuanye Group, a name not previously seen by experts who track cyber extortion groups. Such groups typically contact companies privately before publishing stolen data or publicly claiming responsibility for a breach. The people behind the message provided no evidence that they had compromised ASOS’s Snowflake cloud data environment. Charlotte Wilson, an executive at cybersecurity company Check Point, said: “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note.” She said that the rapid way ASOS shares tumbled after the alert was sent showed how “before the company had even publicly established what had happened, investors were already pricing in the potential consequences.” ASOS, which is traded on the London Stock Exchange, did not respond to a request for comment. An introductory post on the Telegram channel described it as Xuanye Group’s official broadcast outlet, warned about impersonators and said a separate “gateway” channel would direct users to a replacement if the main channel was removed. A later post said: “Regarding ASOS, payment information is not affected.” The group provided no evidence for that claim and did not say what information, if any, it had obtained. The Telegram channel contained no samples of customer data or other material that independently supported the group’s claims. The sole evidence for any hack is the appearance of the message as an ASOS app notification. If confirmed, it would indicate that whoever sent the message had access to at least part of the company’s customer-messaging infrastructure. Snowflake is used by companies to store and analyze large amounts of data. While it can be connected to other business systems, there is no public evidence that ASOS uses Snowflake to send push notifications, or that Tuesday’s alert originated from the ASOS Snowflake environment.
No previous article
No new articles
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79