
Online Fashion Retailer Asos Investigates Extortion Threats Sent Directly Through Customer Phone App
An unauthorized alert warned shoppers of a database breach, but the clothing store says payment records remain secure.
7 Oct 2026
Shoppers opening their phones on Tuesday morning encountered an unexpected threat popping up on their screens from the fashion retailer Asos. A rogue push notification broadcast an alarm that the retailer had been infiltrated, startling customers who usually rely on the application for routine wardrobe purchases.
The unauthorized dispatch appeared around mid-morning British time and took the form of a direct blackmail note. Styled as a message to internal security staff and privacy officers, it claimed that data archives had been compromised, demanded contact via an outside messaging channel, and threatened to release company records publicly if ignored.
The message reached an international audience almost immediately. While the retailer has not disclosed the full count of compromised accounts, user reports came in from France, Ireland, Sweden, and Australia. The company serves roughly 17 million buyers across more than 150 regions, and its mobile software has been installed over 10 million times on Android devices alone.
Asos later clarified that the intrusion originated outside its primary systems. Attackers had gained illicit entry into external third-party software services tied to the retailer, which allowed them to trigger the mass broadcast directly to consumer devices.

According to the store, preliminary reviews suggest that basic personal details may have been exposed during the incident. However, Asos maintained that customer payment card information and login passwords were not affected by the breach.
The retailer followed up with an email advising users to disregard the alert and stay away from the linked channel. Emphasizing that digital storefronts and mobile operations continue to function normally, management urged shoppers to proceed with standard transactions while internal teams examine the intrusion.
Despite the disruption, the company had not submitted a formal breach filing to the UK Information Commissioner's Office immediately after the incident. Regulators typically require prompt notification when sensitive citizen data faces significant risk.
The extortion note specifically singled out Snowflake, a widely used cloud data storage and analysis provider. In response, Snowflake confirmed it was reviewing the matter alongside its client, adding that its own platform had shown no signs of being penetrated.