Original Coverage & Source Attribution: tech-insider.org
Asos customers in the UK, US, Germany and Australia opened their phones on the morning of October 6, 2026 to find a push notification that had nothing to do with a flash sale. Titled “ASOS HACKED,” the alert claimed the fashion retailer’s Snowflake cloud data environment had been “fully compromised” and threatened a public leak unless the company engaged with the senders. Asos shares on the London Stock Exchange fell as much as 13.2% within hours, before paring losses to trade roughly 9% to 10% lower, according to The Record and City AM.
Asos has not confirmed any compromise. The company told customers contacting its support chatbot that it is “aware of the notification and are currently investigating,” per a BBC report cited by multiple outlets. No independent evidence, no customer data samples and no proof of system access have surfaced publicly as of this writing. What has surfaced is a stock price swing, a previously unknown extortion group, and renewed attention on how Snowflake-hosted retail data keeps ending up at the center of 2026’s biggest breach stories.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What the Asos app notification actually said
The message, sent at around 10am BST, was addressed not to shoppers but to Asos’s own staff. It read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It carried a signature reading “xuanyewengateway” and a link to a Telegram channel, according to Infosecurity Magazine.
That detail matters more than the threat itself. Whoever sent the notification was using Asos’s own app infrastructure as the delivery channel, turning a trusted retail notification into what amounts to a ransom note that millions of customers could read on their lock screens. A follow-up post on the linked Telegram channel added one more line: “Regarding Asos, payment information is not affected.” No supporting files, screenshots or database samples accompanied either message.
Who is the Xuanye Group
The Telegram channel behind the notification identifies itself as the official broadcast outlet of a group calling itself Xuanye Group. Researchers who track cyber extortion gangs for a living said the name had not crossed their radar before October 6, per The Record. The channel’s introductory post warned followers against impersonators, a now-common move among extortion crews trying to protect their brand on criminal forums while they shop stolen (or claimed) data to buyers.
An unknown name does not mean an empty threat, and it does not mean a confirmed breach either. Some extortion operations rebrand between campaigns specifically to dodge the reputational baggage of a prior name. Others are opportunists riding the publicity of a real incident, or a credential dump bought secondhand, without having breached anything themselves. Until Asos or a forensic investigator publishes findings, Xuanye Group sits in the same unverified bucket as the claim it is making.
Asos stock price reaction, by the numbers
Markets did not wait for confirmation. Asos shares dropped to 439p during Tuesday trading, which City AM reported as a decline of up to 10% from the prior close. The Record put the intraday low at a steeper 13.2% before the stock recovered some ground to settle closer to a 9% loss. The swing is notable given Asos shares had climbed more than 50% year-to-date heading into October, on the back of a turnaround narrative the company had been selling to investors.
| Metric | Figure | Source |
|---|---|---|
| Notification sent | ~10am BST, October 6, 2026 | Infosecurity Magazine |
| Intraday share price low | Down as much as 13.2% | The Record |
| Share price, trading recovery | Pared to roughly 9%-10% lower, 439p | City AM |
| Year-to-date gain before incident | More than 50% | City AM |
| Active customers globally | Approximately 17 million, across 150+ countries | City AM |
| FY2025 revenue | £2.5 billion | City AM |
A double-digit share price move triggered by an unverified Telegram claim says as much about market nerves around 2026 data breaches as it does about Asos specifically. Investors have watched enough real incidents unfold this year, several of them covered in our rundown of ransomware data theft surging 275% across schools and hospitals, that they are no longer willing to wait for confirmation before selling.
Is the Snowflake breach claim credible?
Security researchers quoted across UK outlets stopped short of calling the claim confirmed, but several said it should not be dismissed either, given the delivery method. Charlotte Wilson of Check Point told The Record: “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned Asos’s own app into their ransom note.”
Marijus Briedis, chief technology officer at NordVPN, framed the tactic the same way in comments to City AM, calling it “unusually brazen” and adding: “The attackers aren’t simply claiming to have breached Asos, they’re publicly telling the company to engage with them or they will leak what they say they have obtained.” Briedis’s point cuts to why this incident is spreading faster than a typical breach disclosure: the extortion demand reached customers before it reached, by all public accounts, Asos’s own crisis communications team.
Jake Moore of ESET told Infosecurity Magazine the episode could become “one of the most visible hacks in history” if the Snowflake claim holds up, warning it could “put a lot of customer data at risk.” Pieter Arntz of Malwarebytes added that any genuine exposure “could reveal a detailed customer picture, from browsing and buying habits to location,” which is a meaningfully different risk profile than a simple password leak. Michele Campobasso of Forescout recommended customers avoid clicking any links tied to the notification and “change their passwords for an extra layer of protection” regardless of how the investigation concludes.
This isn’t Asos’s first data security scare in 2026
October’s notification lands four months after a confirmed, smaller-scale incident at the same company. Asos detected unusual account activity on July 28, 2026 and confirmed unauthorized access the following day, according to eSecurityPlanet. That incident was consistent with credential stuffing: attackers reused usernames and passwords stolen from breaches at other companies to log into Asos customer accounts that reused the same credentials.
What data was exposed in July
The account takeover affected an estimated 138,828 customers globally, with cyber bulletin outlet cypro.co.uk separately reporting around 9,000 of those tied to US-based accounts flagged in state breach notification filings. Exposed information reportedly included customer names, email addresses, delivery and billing addresses, phone numbers, dates of birth and linked social media account details. Payment exposure was limited: card data was restricted to the cardholder’s name, the last four digits of the card and its expiration date. Full card numbers, CVV codes and stored payment credentials were not compromised, per eSecurityPlanet’s reporting.
Two incidents at one retailer within four months, one confirmed and credential-based, one unconfirmed and Snowflake-based, is the kind of pattern that pushes a company from “had an incident” to “has a security problem” in the eyes of regulators and customers alike. It also echoes a dynamic we have tracked elsewhere this year, including OneMain Financial’s breach notifications spanning multiple US states, where a single root cause generates breach disclosures in waves rather than all at once.
Why Snowflake keeps showing up in breach headlines
Snowflake is a cloud data warehouse used by thousands of companies to store and query massive customer datasets, not a retailer itself. That distinction became infamous in 2024, when a group tracked by Mandiant as UNC5537 used credentials previously stolen through infostealer malware to log into Snowflake customer accounts that had no multi-factor authentication enabled. The campaign reached roughly 165 organizations, according to Wikipedia’s summary of public reporting on the incident.
The 2024 campaign’s scale, in numbers
AT&T disclosed that attackers stole call and text records covering nearly all of its wireless customers, around 109 million people. Ticketmaster data covering an estimated 560 million customer records turned up for sale. Santander confirmed exposure affecting roughly 30 million customers across Chile, Spain and Uruguay. The Justice Department later said victims paid more than $2.5 million in ransom combined, with roughly 100 million people affected across the campaign.
| Company | Year | Reported scale | Attack method |
|---|---|---|---|
| AT&T | 2024 | ~109 million customers (call/text records) | Stolen credentials, no MFA on Snowflake account |
| Ticketmaster | 2024 | ~560 million customer records offered for sale | Stolen credentials, no MFA on Snowflake account |
| Santander | 2024 | ~30 million customers (Chile, Spain, Uruguay) | Stolen credentials, no MFA on Snowflake account |
| Asos (confirmed) | 2026 | 138,828 customers | Credential stuffing / account takeover |
| Asos (unconfirmed) | 2026 | Unknown, claimed “fully compromised” | Claimed Snowflake instance compromise |
No public reporting has confirmed that Asos’s current scare traces back to the same 2024 campaign or its aftermath. The parallel is the attack surface, not necessarily the attacker: a cloud data platform that holds enormous volumes of customer records, and a threat actor betting that the mere mention of “Snowflake” now carries enough credibility on its own to spook a public company’s shareholders.
How push notification extortion differs from traditional ransomware
Classic ransomware encrypts files and demands payment to unlock them. Classic data extortion steals files quietly and threatens to publish them unless paid, the model behind groups our coverage has tracked extensively, including ShinyHunters’ long run of high-profile claims and the FBI’s own confirmed breach earlier this year. What Xuanye Group did differently is skip the private negotiation step entirely and broadcast the threat through the victim’s own customer-facing channel.
That is a pressure tactic aimed at the stock price and the brand, not just the IT department’s inbox. It forces a public company to respond in public, on a timeline set by the attacker rather than its own incident response plan. Whether or not Xuanye Group holds real Asos data, the approach already achieved one goal: a double-digit share price move within hours, without a single leaked record to verify the claim against.
Market impact: what a 13% swing says about breach disclosure
Public companies increasingly get punished by markets before they finish their own forensic review. That dynamic shows up across 2026’s breach disclosures generally, and it raises the stakes for how fast a company like Asos can move from “investigating” to a substantive update. Cyber insurance has become part of that calculus for many retailers managing this exposure, a trend covered in our look at how Coalition, Chubb and At-Bay are pricing cyber risk in 2026.
Asos’s YTD rally going into October makes the stock particularly sensitive to bad news right now. A company trading on a turnaround story has more downside exposed to a headline like “ASOS HACKED” than one already priced for distress. Shareholders are, in effect, pricing in the possibility of a confirmed breach well before Asos’s own investigators reach a conclusion.
Regulatory and legal exposure under UK and EU data rules
If Asos confirms any customer data exposure tied to either the July account takeovers or the October Snowflake claim, UK GDPR and the Data Protection Act require notifying the Information Commissioner’s Office within 72 hours of becoming aware of a reportable breach. No public confirmation of an ICO filing tied to the October incident has surfaced as of this writing. Companies operating across the UK, US, Germany and Australia, the four markets where customers reported receiving Tuesday’s notification, also face a patchwork of separate state and national breach notification laws that can each trigger independently.
That multi-jurisdiction exposure is exactly what complicated Asos’s July account takeover disclosure, which generated separate state-level filings in the US on top of whatever UK and EU process applied. A confirmed October breach covering a Snowflake instance, given the platform’s global customer footprint, would likely multiply that regulatory surface area considerably.
What Asos customers should do right now
Security researchers quoted across this story converged on the same practical advice despite disagreeing on how serious the underlying claim is. Kamran Bahdur of FLR Spectron told Infosecurity Magazine the claim “should be taken seriously and treated as a potential extortion attempt,” even without confirmation. Forescout’s Campobasso recommended avoiding any links shared in connection with the notification and resetting Asos account passwords as a precaution.
- Do not click the Telegram link included in the “ASOS HACKED” notification, regardless of curiosity about the claim.
- Change your Asos account password now, and avoid reusing it on any other site, which is the exact weakness that enabled July’s confirmed breach.
- Enable two-factor authentication on the Asos account if the option is available in account settings.
- Watch for phishing emails or texts impersonating Asos support in the days following a high-profile breach claim like this one.
- Monitor bank and card statements for unfamiliar charges, even though reports indicate full payment card numbers were not part of the July exposure.
Competitive and industry context: retail cybersecurity in 2026
Asos is far from alone among retailers managing credential-based attacks this year. The broader pattern, stolen login details recycled against new targets rather than retailers being breached directly at the source, has driven a wave of account-security investment across online retail, echoing the push toward passwordless authentication we detailed in our piece on passkeys cutting help desk costs and breach risk. Competitors including ASOS’s direct rivals in fast fashion e-commerce have faced similar credential-stuffing waves in 2026, though none has yet reported anything resembling the scale claimed, unverified, by Xuanye Group.
What sets this moment apart from a typical retail breach cycle is the extortion delivery mechanism itself. Turning a retailer’s own push notification system into the attack’s megaphone is a tactic that, if it proves effective at moving a stock price without verified proof, is likely to get copied against other companies running customer-facing mobile apps tied to cloud data platforms.
Predictions: what happens next
Several outcomes look likely based on how similar incidents have played out in 2026 and in the 2024 Snowflake campaign that preceded it, though these remain analysis rather than confirmed fact.
- Asos will likely issue a formal statement within days, either confirming limited exposure or stating its investigation found no evidence of a Snowflake compromise, following the pattern of most unverified extortion claims this year.
- Expect copycat notifications at other retailers using Snowflake or comparable cloud data platforms, given how much attention the push-notification delivery method generated relative to its cost to execute.
- Regulatory attention to MFA enforcement on cloud data warehouse accounts will likely increase, regardless of whether the Asos claim is confirmed, given the direct line back to the unsecured accounts behind the 2024 campaign.
- Asos’s share price is likely to stay volatile until a confirmed outcome is published, consistent with how markets have repriced other unresolved 2026 breach claims.
- Cyber insurance underwriters are likely to scrutinize retail clients’ Snowflake and cloud data warehouse configurations more closely during 2027 renewal cycles.
The bottom line
Nothing about the October 6 notification has been independently verified. Asos has not confirmed a breach, Xuanye Group has not published evidence, and no customer data has surfaced publicly. What is verified is that a previously unknown extortion group found a way to cost a public retailer a double-digit share price swing in a single morning, using nothing more than access to its own app notification system and a claim nobody can yet check. That alone should worry every company storing customer data in a shared cloud platform, confirmed breach or not.
Frequently asked questions
Has Asos confirmed it was hacked?
No. As of this writing, Asos has not issued a formal statement confirming any compromise. The company told customers contacting its support chatbot it is “aware of the notification and are currently investigating,” per BBC reporting cited by multiple outlets.
What did the Asos hack notification say?
The push notification was titled “ASOS HACKED” and read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It linked to a Telegram channel run by a group calling itself Xuanye Group.
Who is the Xuanye Group?
Xuanye Group is a name that had not previously appeared in public tracking of cyber extortion gangs before October 6, 2026, according to The Record. No independent confirmation of the group’s capabilities or prior activity has been published.
How much did Asos shares fall?
Asos shares fell as much as 13.2% intraday before paring losses to trade roughly 9% to 10% lower, reaching 439p at one point, according to The Record and City AM.
Is this related to Asos’s July 2026 data breach?
No confirmed link has been reported. The July incident was a confirmed credential-stuffing attack affecting an estimated 138,828 customers, detected July 28 and confirmed July 29. The October notification is a separate, unconfirmed claim involving Snowflake.
Was payment information exposed?
In the confirmed July breach, exposed payment data was limited to redacted card details, the cardholder’s name, the last four digits and the expiration date. Full card numbers and CVV codes were not compromised. The October group itself stated “payment information is not affected” in a follow-up Telegram post, though this claim is unverified.
What should Asos customers do?
Security researchers recommend not clicking any links tied to the notification, changing your Asos password, enabling two-factor authentication where available, and watching for phishing attempts impersonating Asos support in the days following the claim.
Does this relate to the 2024 Snowflake breach involving AT&T and Ticketmaster?
No confirmed connection has been reported. The 2024 campaign, attributed to a group tracked as UNC5537, exploited Snowflake accounts without multi-factor authentication across roughly 165 organizations. The current Asos claim references the same platform but no public reporting ties it to the same attackers.
{
“@context”: “https://schema.org”,
“@type”: “NewsArticle”,
“headline”: “Asos Data Breach: Hackers Threaten Leak [2026]”,
“datePublished”: “2026-10-06 13:27:00”,
“image”: “https://tech-insider.org/wp-content/uploads/2026/10/asos-data-breach-shares-drop-13-percent-2026-1.webp”,
“author”: {
“@type”: “Organization”,
“name”: “Pune.Media Editorial Desk”,
“url”: “https://pune.media”
},
“publisher”: {
“@type”: “Organization”,
“name”: “Pune.Media”,
“logo”: {
“@type”: “ImageObject”,
“url”: “https://pune.media/wp-content/uploads/logo.png”
}
},
“isBasedOn”: “https://tech-insider.org/asos-data-breach-shares-drop-13-percent-2026/”,
“mainEntityOfPage”: “https://tech-insider.org/asos-data-breach-shares-drop-13-percent-2026/”,
“creativeWorkStatus”: “Editorial-assisted Curation”,
“comment”: {
“@type”: “Comment”,
“text”: “This article was curated, verified, and structured under organizational human editorial guidelines by the Pune.Media Editorial Desk.”
}
}

![Asos Data Breach: Hackers Threaten Leak [2026] Asos Data Breach: Hackers Threaten Leak [2026]](https://pune.media/wp-content/uploads/2026/10/1791293565-696x398.webp)