ASOS hackers used the app’s own alerts to send threats. Shares fell 10%
A group called Xuanye pushed a ransom-style alert through the ASOS app. ASOS says names and contact details may be exposed, but not cards or passwords.

Photo: RDNE Stock project / Pexels
Shoppers using the ASOS app received a push alert on Tuesday, 6 October, that read “ASOS HACKED”. The message came from a group calling itself Xuanye. It told the retailer’s data and IT staff to get in touch or see stolen data published, BleepingComputer reported. The alerts started around 5am US Eastern time.
ASOS shares fell 10% the same day, Reuters reported. Before the attack the stock was up about 60% this year.
ASOS says names and contact details may be exposed
ASOS confirmed that someone got into third-party platforms it uses to talk to customers. It said “basic personal information” such as names and contact details may have been accessed. The company said it does not believe card data or account passwords were affected. It cut access to the platforms and brought in outside advisers and the relevant authorities.
The group claimed it had broken into the retailer’s Snowflake data warehouse. ASOS has not confirmed that claim. It has not said how many customers are affected. The site and app kept running as normal.
The attack turned the app’s alert channel against ASOS
Most data breaches reach customers through an email from the company, days or weeks later. This one reached them first, through the brand’s own channel. ASOS then had to send a second in-app notice telling users to ignore the first and not to click outside links.
That order of events makes the response harder. Customers saw the threat before they saw any statement. The tone of the first official message has to calm people down without confirming details the company has not checked yet. ASOS kept its statement short and avoided the hackers’ claims.
The case adds to a busy year for retail crisis teams. Earlier this autumn Zara pulled a children’s Halloween costume within hours of online criticism. Online fashion is also under price pressure, with Shein’s European sales down 13.9% in the second quarter.
Who controls a brand’s push notifications
For brands with an app, the useful check today is simple. List every outside tool that can send a push message, an email or an SMS in your name. Then check who holds the login for each one and whether it uses two-step sign-in. A breach of any of them puts words in your brand’s mouth, in front of every customer at once.
Sources
- BleepingComputer — Notification text, ASOS statement, Xuanye group, 6 Oct 2026
- Reuters via KFGO — Share price fall, ASOS statement, context, 6 Oct 2026