Skip to content

Asos shares fall 10.6% after hack sends blackmail alert to app users

The retailer says payment cards and passwords were not compromised, but names and contact details might have been accessed.

6 October 2026

Asos shares fall 10.6% after hack sends blackmail alert to app users - Worthbury

Shares of Asos closed down 10.6 percent at 449 pence on Tuesday as investors tried to assess the damage from an exceptionally visible security breach. Earlier in the day, people using the retailer's app began posting screenshots of a push alert that appeared designed to extort the company.

The message named the firm's data protection officer and IT team directly. "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," the alert read, apparently referring to Snowflake, the cloud-based data storage company.

Shoppers found themselves caught in the middle of a negotiation aimed at the company, a position customers are rarely placed in. Asos confirmed what it called an "unauthorized customer notification," a breach that co-opted a channel it uses to talk to shoppers.

"We are investigating unauthorized activity involving third-party platforms that we use to communicate with customers," the company said. "We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."

Customers' personal information, including names and contact details, might have been accessed, the firm said. But it added that it does not believe payment-card information or passwords were compromised, the two pieces of data that would turn a nuisance into a liability.

"Our website and app are operating as normal, with no current disruption to any aspects of our operations," Asos said. "Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate."

What the company did not say

Asos also said it holds "cyber security insurance with a large global provider, including business continuity insurance," and that it is "too early to quantify any potential impact on trading." Shareholders therefore have no figure for what the breach might cost.

The alert addressed the data protection officer by title, so whoever sent it knew something of the company's internal roles. The reference to Snowflake points to a specific third-party cloud instance, though Asos itself has not confirmed that Snowflake was the route in.

Asos did not disclose how many customers received the push notification, how the attackers got access, or what data they claim to hold. Those are the facts a blackmail attempt depends on, and none of them has been made public so far.

Why an app alert is unusual

Threats against online retailers are nothing new, but they usually happen away from the consumer's eye. It is rare for app users to have the push-alert function taken over on their own phones, which puts ordinary shoppers in the crossfire.

Even if the hackers control nothing more than the ability to trigger an alert on shoppers' phones, that alone is the power to disrupt the relationship between retailer and customer, which matters most to an online business.

Many details are still unknown, but the incident looks like a parable for fashion in the digital age, particularly as AI increases the ability of attackers to break into systems that were once seen as secure.

The market's response was immediate. A fall of 10.6 percent in a single session means investors weighed the cost of a breach, the hit to customer trust, and the unknown scope of what the attackers hold, all at once.

For a retailer whose customer relationship runs through an app, the tool that carried the extortion demand is the same one that carries its marketing and its orders. Asos said its website and app were working normally on the day.

Asos has said it will provide an update if the situation changes, which leaves the next disclosure without a fixed date.

Support the content you love — it’s free 🎉

Add Worthbury as a preferred source on Google. Our stories will be more likely to appear in Google’s Top Stories. It’s free and supports our team. Thank you!

Add as preferred source

You can remove us any time in Google’s source preferences.

This briefing is published daily using an AI-powered system crafted by Worthbury's team and finely tuned to meet our editorial standards. While we continuously test and review the output, mistakes can sometimes happen. Tell us if you spot one.