ASOS Investigates App Security Breach After Chilling 'Engage With Us' Extortion Alert Hits Users
Fashion giant launches urgent security probe after alarming 'ASOS hacked' push notifications direct shoppers to a Telegram extortion channel

An apparent extortion threat delivered through ASOS's own mobile app has raised fears that alleged attackers may have reached both customer data and the systems the retailer uses to communicate with shoppers.
ASOS began investigating on 6 October 2026 after users received an 'ASOS hacked' notification. Addressed to the company's data protection officer (DPO) and information technology team, the message claimed the sender had 'fully compromised' an ASOS Snowflake instance and warned, 'Engage with us, or we will leak it.'
The alert directed recipients to a Telegram channel called Xuanye Group Gateway, which appeared to have been newly created. The BBC reported that dozens of customers contacted the broadcaster after seeing the message.
The company has not confirmed that its Snowflake environment or ASOS customer data was breached. Meanwhile, its website and app remained operational, The Guardian reported. ASOS stock plummeted by as much as 11 per cent following the security scare.
Why the Alleged Snowflake Data Breach Claim Causes 'Real Worry'
Companies use Snowflake, a cloud data platform, to store, process and analyse information. Retail data in such systems can include transactions and demographic details, including clothing sizes and body measurements, although ASOS has not said what information may have been affected.
Dray Agha, senior manager of security operations at Huntress, said it was 'a real worry if cyber criminals have indeed accessed it as they claim.' He characterised the tactic as a form of public extortion designed to pressure the retailer into negotiating quickly.
Charlotte Wilson, head of enterprise at cyber-security company Check Point, told the BBC that the incident would be deeply serious if verified because the senders appeared to have used ASOS's app as a ransom note.
According to Sky News, the delivery method may point to access beyond the data platform named in the alert. Dan Bird MBE, field chief technology officer for Europe, the Middle East and Africa (EMEA) at Horizon3, said an app push notification would normally come from a system separate from Snowflake. If both forms of access are genuine, compromised credentials may have opened more than one system.
Phishing May Be the First Risk for Customers
Experts said shoppers should expect criminals to exploit the uncertainty. Fraudulent emails or texts could claim that an ASOS account has been compromised, offer a refund or direct recipients to a password-reset or payment-verification page.
Customers should avoid links in unexpected messages and instead open the official ASOS app or type the company's web address directly. They should also treat the Telegram link in the original notification as suspicious while the investigation continues.
Marijus Briedis, chief technology officer at NordVPN, said the way the alert was delivered suggested that someone had gained unauthorised access to at least part of ASOS's systems, although the extent of any intrusion remained unknown. Access to a trusted company channel makes a threat more convincing and potentially more damaging, he added.
Attack Lands During ASOS Recovery
The company has 16.4 million active customers and about 2,800 employees, and it sells in more than 150 countries.
Its market value had recovered to about £602 million before the security scare, after falling from a peak of roughly £7 billion to around £320 million amid tougher competition and pressure on consumer spending. Shares then dropped by as much as 11% after news of the notification emerged.
The investigation must now establish whether data was extracted, what systems were accessed and which customers, if any, were affected. Until ASOS confirms those points, the fact that a threatening message reached users through its app does not prove that the alleged attackers obtained all the data they claimed.
No public confirmation currently shows that customer data was accessed or extracted. The incident follows cyber-attacks on British retailers Marks & Spencer, the Co-op and Harrods in 2025.
Cybersecurity specialists warned that the unprecedented delivery method suggests attackers may have compromised multiple internal systems beyond the data platform, raising serious concerns for millions of active shoppers across more than 150 countries.
© Copyright IBTimes 2026. All rights reserved.

