
Intruders Hijack ASOS Shopping App to Broadcast Ransom Demand to Customers
A rogue alert sent directly to customer phones claimed a major server breach, sending the British retailer's share price tumbling.
6 Oct 2026
Shoppers opening their phones on Tuesday found an unexpected extortion message delivered directly through the ASOS mobile application. Instead of typical marketing promotions, a push notification declared that the British online clothing seller had been compromised.
The alert addressed the company's data protection officer and technical staff by name of role. It claimed that an external data platform used by the retailer was breached and threatened to publish confidential files unless company managers made contact.
The intrusion immediately rattled financial markets. Shares of the London-listed retailer dropped by more than ten percent during Tuesday trading as shareholders absorbed the news before the firm could clarify the situation.
Recipients of the phone alert were directed to a channel on the Telegram messaging service run by a previously unknown entity calling itself Xuanye Group. Security researchers monitoring extortion networks note that this name had not surfaced in earlier cybercrime tracking.
Extortionists routinely contact corporate victims in private before releasing records or publicizing an attack. In this instance, the attackers chose an unusually public channel by commandeering the retailer's direct conduit to its customer base.

The Telegram channel provided no samples or evidence showing that private customer records had actually been taken. The operators offered no technical documentation to back up their assertion of an intrusion.
A follow-up message on the channel stated that shopper payment details were unaffected by the incident. As with the initial threat, the group offered no verification for that claim and did not specify what files they possessed.
The warning singled out Snowflake, a widely used cloud platform where enterprises store and analyze massive databases. Public records do not show that ASOS uses this analytical platform to dispatch mobile push alerts, casting doubt on the attackers' narrative of how the breach occurred.
Security specialists observed that the only confirmed compromise so far is the messaging tool itself. To display text on customer devices, the perpetrators needed access to the software infrastructure that pushes notifications to shoppers.
Analysts at the security firm Check Point noted the brazen tactic of transforming an organization's proprietary software into an extortion billboard, pointing out that markets responded to the threat well before the retailer could determine the facts.
ASOS did not issue an immediate statement or answer inquiries regarding the incident. Whether any sensitive files left the retailer's databases remains unconfirmed.