Hackers Turned ASOS’s Own App Into a Ransom Note — and the Stock Crashed 13%

A smartphone glowing red in darkness, its lit screen evoking an urgent phone alert.

On Tuesday, thousands of Asos shoppers got a notification from the retailer’s own app. It was addressed to the company’s data protection officer and IT department, and its subject line was, bluntly: “ASOS HACKED.”

According to the message, hackers claimed to have “fully compromised” a Snowflake data instance belonging to the British fashion retailer, and threatened to leak customer data unless Asos engaged with them — even directing shoppers to a Telegram account. Asos shares crashed more than 13% on the London Stock Exchange. AFP reports that Asos has launched an investigation, with Britain’s National Cyber Security Centre offering assistance.

The Breach Claim Is Unconfirmed — the Notification Was Real

This is the part that matters: nobody has confirmed a breach actually happened. A Snowflake spokesperson said the company “found no compromise of the Snowflake platform” so far, and the investigation is ongoing. Asos told shareholders it was “too early” to quantify any trading impact, and the UK’s data watchdog said it had not received a formal report.

So what we know for certain is that the notification was real — customers really received it through the Asos app. Whether the underlying hack claim is real is still open. That distinction is everything.

The New Extortion Playbook

Here is the angle the straight wires missed. Classic ransomware works like this: encrypt the data, negotiate privately, leak a sample. This was different. By pushing a ransom message directly onto customers’ phones — through the victim company’s own app — the attackers recruited thousands of shoppers as involuntary pressure on Asos. As cybersecurity analysts told Reuters, sending a ransom demand straight to consumer devices is “an aggressive extortion tactic designed to force the business into a quick negotiation” — because panic from customers piles on far more pressure than a quiet email to the IT department.

It is extortion as performance. The 13% stock drop did the attackers’ negotiating for them.

The Snowflake Shadow

The claimed vector — a Snowflake instance — will ring alarm bells for anyone who followed the 2024 wave of attacks on retailers’ cloud data warehouses. Snowflake says its platform is clean; whether a specific customer’s instance was mishandled is a separate question, and Asos has not said. For now, the honest read is: claim made, claim unverified, investigation live.

Why This Matters

Even if this turns out to be a bluff, the tactic is the story. A push notification is the most trusted channel a brand owns — it bypasses spam filters, phishing warnings, and common sense, because it arrives inside the app you already trust. Weaponizing it turns a retailer’s own communication infrastructure into a hostage. Expect copycats: every company with a mobile app just learned its notification channel is an attack surface, and every security team should be asking who can push to their users and how that access is guarded. For shoppers: ignore the Telegram account, do not engage with the message, and verify through Asos’s official channels only. And if a company ever tells you — via its own app — that it has been hacked, check the news before you panic. Sometimes the ransom note is the whole attack.

Meanwhile in Tech News: Denmark’s 8.8 million-record breach is its biggest hack ever — here’s the timeline. Meanwhile in Tech News: NYC forces AI giants to testify under oath.

Written by
Nathan covers breaking tech news — Big Tech earnings, antitrust battles, cybersecurity incidents, and the stories moving the industry day to day.