Asos shares crater after ‘hackers’ threaten data leak
Asos shares have tumbled after customers were told the online fashion seller’s systems had been “fully compromised” by hackers.
Users of the Asos app received a push notification on Tuesday morning titled “ASOS HACKED”, in an apparent attempt by the attackers to contact the company’s data protection and IT teams.
Asos said on Tuesday afternoon that it is investigating the incident, which it does not think posed a risk to customers’ passwords or payment information. Shares in the London-listed retailer fell by as much as 10 per cent following the apparent hack, to 439p.
“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance”, the message read. “Engage with us, or we will leak it”. The notification included a link to a Telegram chat.
The apparent hackers later said that the Asos app remains safe to use, in a statement posted to Telegram. They said: “The affected organisations app is safe to use. The incident involves customer information, it is safe on our server, and it will not be touched for a designated period.
“Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident.”
Snowflake is a cloud platform used to process data like clothing sizes and body measurements. This platform also allows the user to send notifications to clients’ phones.
A spokesperson for Asos said: “We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.
“Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.
“Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”
Asos has cyber security insurance from a “large global provider,” the spokesperson added. The group said it cannot yet estimate the impact of the incident on its sales.
The operators of Snowflake said later on Tuesday that the platform had not been compromised, shedding further doubt over the nature of the cyber incident. “At this time, we can report that we have found no compromise of the Snowflake platform,” the firm said.
Apparent hack ‘brazen and threatening’
Reports of the notification emerged from users in several countries, including the UK, US, Germany and Australia. The incident could trigger reporting requirements if Asos confirms personal data has been compromised.
Under UK data protection rules, organisations generally have 72 hours to notify the Information Commissioner’s Office after becoming aware of a personal data breach where it poses a risk to people’s rights and freedoms. Those affected must also be informed without undue delay where a breach is likely to pose a high risk.
Marijus Briedis, the chief technology officer of online services provider Nord VPN, said the message sent by the apparent hackers was “unusually brazen and threatening”.
He added: “The attackers aren’t simply claiming to have breached ASOS – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.
“What makes it even more concerning is how that threat appears to have been delivered. A message apparently written for ASOS’s data protection and IT teams has instead been pushed directly to customers through the company’s own app notification system.”
Asos has around 17m active customers globally and operates across more than 150 countries. The London-listed retailer has been attempting to revive its fortunes following several difficult years for online fashion, reporting revenue of around £2.5bn in 2025.
Chief executive José Antonio Ramos Calamonte had been making progress, with the group’s shares up by more than 50 per cent this year before Tuesday’s incident. Last month, Asos upgraded its pre-tax earnings target to between £150m and £180m owing to “materially improved profitability”.
British retailers have suffered a number of cyber attacks in recent years, with Marks & Spencer, Co-op and Harrods among those affected.
Asos was approached for comment.