
Online Retailer ASOS Investigates Threat Sent Directly to Customers Through Its Phone App
Shoppers received an unexpected warning on their mobile screens demanding contact from company leaders before private data is published.
6 Oct 2026
Shoppers using the ASOS mobile software saw a startling note appear on their screens on a Tuesday morning. The message was sent out through the retail platform's own alert channel, reaching a wide group of shoppers across the service.
The text spoke directly to the digital security staff and the data protection officer, an internal employee charged with guarding user records. It declared that the company's installation of Snowflake, an online platform used to store and examine massive amounts of data, had fallen completely into outside hands.
The intruders demanded that ASOS get in touch with them right away, threatening to publish company files if the firm stayed silent. The dispatch also directed readers to an address on the messaging network Telegram.
Records inside that newly started chat channel pointed to a group calling itself Xuanye Group. Observers noted that this name has no known record of past digital break-ins, and the room contained no formal demands for cash or goods.
The channel also claimed that user banking records had not been touched. Even so, observers stressed that shoppers have no solid foundation to trust such words from intruders.
ASOS did not reply when asked for an explanation, and the firm posted no early updates across its social feeds. The underlying shop page and the shopping program themselves continued to operate as normal throughout the day.

The public shock prompted an immediate reaction on financial exchanges. Shares in the company dropped by 12.5 percent within hours of the dispatch, wiping away approximately 70 million pounds in company value.
This sudden drop landed on a business already dealing with tighter balances. The group made 2.5 billion pounds in revenue during 2025, down from 2.9 billion the prior year, leading to an operating loss of 212 million pounds alongside a slide to 17 million active shoppers.
Legal specialists noted that verified data losses bring legal exposure in Britain. Rules under UK GDPR and the Data Protection Act require firms to alert the Information Commissioner's Office within 72 hours if customer rights face hazards, potentially leading to steep financial fines.
Security specialists urged everyone who received the alert to avoid opening the link or joining the chat room. They warned that attackers frequently exploit such chaos to run fake emails and texts that pretend to help users fix orders or recover accounts.
Advisers suggested that shoppers type the store website directly into a browser to change their login codes, rather than tapping any incoming links. They also recommended updating identical credentials across other websites, preferably through dedicated password managers.
It remains unverified how far inside the retailer's systems the intruders reached, or whether any consumer records were actually stolen.