Home » ‘WE WILL LEAK IT’: ASOS customers receive terrifying ransom warning from fashion giant’s own app

‘WE WILL LEAK IT’: ASOS customers receive terrifying ransom warning from fashion giant’s own app

by Simon Jones Tech Reporter
6th Oct 26 10:58 am

ASOS is investigating a suspected cyberattack after customers received an extraordinary notification through the fashion retailer’s own mobile application claiming hackers had “fully compromised” its Snowflake data platform and threatening to leak information.

The incident illustrates the growing commercial risk posed by cyberattacks in which criminals seek not only to penetrate corporate systems but also to exploit the trust between companies and their customers.

The message, delivered to users on Tuesday morning, was addressed directly to ASOS’s data protection officer and IT department.

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” it said.

The notification also directed recipients to a Telegram group, apparently providing a channel through which the attackers sought to communicate with the company.

ASOS has not confirmed that customer data was stolen, and the precise nature and extent of any unauthorised access remain unclear. Reuters said it was unable to independently verify reports of the alleged hacking, while ASOS acknowledged awareness of the reports but did not confirm a breach.

The distinction is important. A claim that a company’s Snowflake environment has been compromised does not in itself establish that customer information was accessed or downloaded.

Snowflake is a cloud-based data platform used by businesses to store, process and analyse large volumes of information. If the attackers’ claims prove accurate, investigators will need to establish which systems were accessible, what information was stored there and whether data was actually extracted.

For ASOS, the immediate concern is compounded by the apparent control of its customer communications channel. Delivering a ransom message through the official application gives an attacker a degree of credibility that conventional phishing emails cannot easily replicate.

Charlotte Wilson, head of enterprise at security firm Check Point, described the apparent incident as particularly serious because the attackers appeared to have turned ASOS’s own application into a ransom note.

“Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company,” she said. “The fact an attacker may have been able to hijack that relationship and send a threat directly to customers demonstrates how quickly a cyber incident can move from the server room to the front page, and then straight into the market value of a business.”

That market reaction was immediate. ASOS shares fell sharply following reports of the incident, with Reuters reporting a decline of more than 11 per cent.

The episode highlights how cyber risk has become inseparable from corporate valuation. Investors must assess not only the potential cost of stolen data but also disruption to operations, regulatory exposure, reputational damage and the possibility of prolonged customer distrust.

Marijus Briedis, chief technology officer at NordVPN, said the method of communication was particularly concerning.

“This is an unusually brazen and threatening message,” he said. “The attackers aren’t simply claiming to have breached ASOS – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.”

For customers, however, the most immediate danger may come from criminals exploiting uncertainty around the incident.

Cybersecurity specialists have warned that a high-profile breach creates ideal conditions for secondary phishing campaigns. Fraudsters can exploit public concern by sending messages purporting to be from ASOS and asking customers to reset passwords, confirm payment information, review orders or claim refunds.

Customers should therefore avoid links contained in unsolicited messages and instead access ASOS directly through its official application or website.

They should also avoid assuming that personal or payment information has been stolen until ASOS establishes what happened.

The retailer, founded in London in 2000, has around 17mn customers and reported revenue of £2.5bn in 2025.

The scale of the business means the consequences of a confirmed breach could extend well beyond the immediate cost of investigating the intrusion.

The incident also underlines a broader shift in cybercrime. The objective is increasingly not simply to steal information but to weaponise the systems through which companies communicate with their customers.

If the alleged compromise is confirmed, ASOS will face the more difficult task of determining not merely how attackers entered its systems, but how far they were able to travel — and whether the company’s own digital infrastructure became an instrument for the attack.

Leave a Comment

You may also like

CLOSE AD