Advertise X LinkedIn
Dow Jones 51,512.66 ▲0.48%S&P 500 7,827.70 ▲0.69%Nasdaq 27,645.78 ▲0.61%Russell 2000 2,834.55 ▼0.44%S&P/TSX 35,659.97 ▲0.40%Bovespa 206,030.04 ▼0.43%DAX 25,449.19 ▲0.77%FTSE 100 10,541.69 ▲0.42%CAC 40 7,865.07 ▲0.40%Euro Stoxx 50 6,272.23 ▲0.48%IBEX 35 19,444.20 ▲0.75%FTSE MIB 51,261.40 ▲0.87%Nikkei 225 70,683.98 ▲1.05%Shanghai 3,842.20 ▲0.31%Hang Seng 24,280.56 ▲1.00%KOSPI 6,941.39 ▼0.89%Nifty 50 22,776.10 ▲0.98%ASX 200 8,735.70 ▲0.57%AAPL 332.90 ▲0.00%NVDA 239.77 ▲0.36%MSFT 531.64 ▲1.23%GOOGL 347.16 ▲0.20%AMZN 255.65 ▲1.69%META 743.02 ▲0.15%TSLA 380.22 ▲0.39%JPM 331.31 ▲0.18%BTC 85,565.00 ▲0.28%ETH 2,694.75 ▼0.21%SOL 120.48 ▲0.52%EUR/USD 1.1262 ▲0.37%USD/INR 96.42 ▲0.14%GOLD 4,190.00 ▲0.80%CRUDE 89.61 ▲0.20%
Stocks

Asos Investigates App ‘Hack’ Alerts as Shares Fall 12%

Asos is investigating whether hackers accessed its systems after thousands of customers received a push notification through the retailer's own app titled "Asos hacked", according to Theguardian. The alert directed recipients to a message

Benjamin
By Benjamin, Staff writer
· 4 min read
Smartphone on a desk showing an unread app notification beside a laptop and parcel
In this article4 sections
  1. 01Key facts
  2. 02What security researchers say about the Asos alert
  3. 03Why it matters
  4. 04What to watch

Asos is investigating whether hackers accessed its systems after thousands of customers received a push notification through the retailer’s own app titled “Asos hacked”, according to Theguardian. The alert directed recipients to a message on the Telegram messaging service.

The notification read: “Dear ASOS DPO [data protection officer] and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it,” followed by the Telegram link. Asos shares dived almost 12% on the London Stock Exchange, later trading down 13.3%, making them the biggest faller on the FTSE 250 index. The website and app appeared to keep operating on Tuesday morning, and it is understood the company is still investigating whether any hack occurred.

Also read: Nike Posts Mixed Quarter and Reveals Layoffs in Pace Overhaul

Key facts

  • The notification was sent to thousands of Asos app users on Tuesday and was titled “Asos hacked”.
  • The message told Asos’s data protection officer and IT team it had “full compromised the Snowflake instance”.
  • Asos shares fell almost 12%, later widening to 13.3%, the biggest decline on the FTSE 250.
  • Snowflake is a cloud platform used to store, process and analyse data including transactions and demographic information such as clothing sizes and body measurements.
  • Marks & Spencer, the Co-op, Harrods and carmaker Jaguar Land Rover have all been targeted by cyber attackers over the past two years.

What security researchers say about the Asos alert

Dray Agha, senior manager of security operations at the online security firm Huntress, said Snowflake is a large cloud database where retailers typically keep sensitive customer information, and called the incident “clear public extortion”. He advised shoppers to watch for targeted phishing attempts while awaiting official confirmation of a breach.

Marijus Briedis, chief technology officer at NordVPN, described the notification as unusually brazen, noting that a message apparently written for Asos’s data protection and IT teams was pushed straight to customers through the company’s own app. He said customers should not assume their personal or payment details have been taken, and urged them to reach the Asos site or app through their own bookmarks rather than links in unexpected messages.

Also read: Kroger has closed at least 39 stores across 9 banners as part of its 60-store overhaul

Tatyana Shishkova, lead security researcher at the anti-virus provider Kaspersky, said attackers able to reach people through a trusted channel can quickly undermine confidence, and warned organisations against drawing conclusions from cybercriminals’ own claims. Recent Kaspersky investigations, she said, show criminals increasingly relying on misconfigurations and legitimate tools already inside a company’s environment.

Why it matters

For Asos, the commercial exposure runs alongside the technical question. Customers grant a retailer access to their phone lock screens because they trust it, and reusing that channel to deliver a threat undermines genuine messages too. Marty Bauer, ecommerce expert at the software company Omnisend, noted that push automations had a 22.9% conversion rate last year among brands using its platform, and said switching notifications off or disengaging could hit repeat sales.

The timing adds pressure. Black Friday is approaching, and Asos is midway through a turnaround programme as it tries to reverse a sales decline and return to profit. The company, which owns Topshop and Miss Selfridge, has 17 million customers in more than 150 countries and employs 2,800 people, with the UK accounting for 49% of first-half revenue.

The incident follows a run of attacks on British retailers. Marks & Spencer and the Co-op suffered stock shortages, and M&S closed its website for several weeks while cleaning its systems.

What to watch

The coming days will show whether Asos confirms a data breach and what its forensic investigation finds about how the notification was sent. Customers should treat unexpected emails or texts claiming to be from Asos with suspicion until the company reports back.

Asos has not published guidance on future earnings or risk exposure tied to this incident, and nothing here should be read as financial advice. Equity markets are volatile and share prices can move sharply on unverified claims.

Benjamin

Written by

Benjamin

Benjamin Carter covers business, finance, and the stock market for StockPil, focusing on the trends and data that matter to everyday investors.

Source: The Guardian

Benjamin
Benjamin · Staff writer

Benjamin Carter covers business, finance, and the stock market for StockPil, focusing on the trends and data that matter to everyday investors.

More from Benjamin →

Read next