ASOS shares plunged more than 10 percent after hackers hijacked the fashion giant’s app to broadcast an extortion threat directly to millions of users.
The London-listed retailer, whose 17 million global customers include nearly half its revenue base in the UK, saw its stock tumble Monday morning when phone screens lit up with a chilling push notification. The alert, dated October 6, declared that attackers had “full compromised the Snowflake instance” and demanded engagement under threat of a data leak, appending a Telegram link for contact.

“If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’ own app into their ransom note,” Charlotte Wilson, head of enterprise at cyber-security firm Check Point, said. “Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company.”
The breach claim centers on Snowflake, a cloud data platform used by major corporations worldwide, though ASOS has not confirmed any commercial relationship with the service. Snowflake has surfaced repeatedly in high-profile security incidents, most notably a breach at Ticketmaster that exposed customer information.
Dan Bird from cyber security firm Horizon3 raised alarms that the intrusion may extend beyond any single database. “Sending a push notification to ASOS’s app users would require access to the company’s notification system, which is separate from the Snowflake data platform the attackers claim to have compromised,” he said. Bird added: “If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door.”

Pete Membrey, chief research officer at ExpressVPN, urged consumers to pause transactions with the retailer pending clarification. Speaking to Sky News, he shared: “Personally, I’d hold off on making any new purchases through the ASOS app or website until the company says more,” Membrey continued: “There’s no public information yet on the level or scope of the attack, so we just don’t know what’s at risk and what isn’t.”
The tech expert noted that while ASOS remained operational, appearances could deceive. “This could change very quickly,” he said. “ASOS might confirm shortly that it’s a limited incident that doesn’t affect customer logins or payments. But until we have that information, a bit of caution is the sensible option.”
Membrey further recommended password changes as a defensive measure, saying users should go onto their ASOS accounts and change their passwords “just in case.”
ASOS had issued no public statement on the incident as of Monday. The company’s silence leaves unresolved whether customer payment data, personal information, or login credentials face exposure, and whether the hackers’ claims of Snowflake penetration reflect actual access or opportunistic bluff.
The attack method itself marks an evolution in ransomware tactics. Rather than conventional dark-web leak sites or encrypted email demands, the perpetrators weaponized a trusted consumer channel, transforming routine brand communication into a mass-distributed threat vector.
The Snowflake connection evokes a pattern of third-party supply chain vulnerabilities that have increasingly drawn regulatory and investor scrutiny. Major enterprises have consolidated data storage with cloud providers, creating concentrated targets whose compromise can cascade across client networks.
ASOS derives 49 percent of revenues from its UK market, making British consumer confidence particularly consequential to financial performance. The share price drop reflected immediate investor anxiety about potential regulatory penalties, remediation costs, and reputational damage in a competitive online fashion sector.
The retailer next reports financial results in November.

