Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data.
The value of Asos’s shares on the London Stock Exchange dived almost 10% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service.
The website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place.
The message sent out to customers said: “Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.”
Snowflake is a cloud platform used to store, process and analyse data including transactions and demographic information such as clothing sizes and body measurements. It also enables push notifications to clients’ phones.
An Asos app notification claiming the retailer has been hacked. Photograph: Screengrab
Dray Agha, the senior manager of security operations at Huntress, an online security firm, said: “Snowflake is a massive cloud database where retailers typically store sensitive customer information – it is a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the Asos mobile app also..”
The link directed Asos customers to a telegram channel operated by an apparent cyber gang called the Xuanye group. Cyber experts said they had not heard of the group before and the push notification might be an attempt to grab wider attention.
“It’s not unusual to see new groups emerge, and often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with ‘credibility’, ” said Aiden Sinnot, the principal threat researcher at the cybersecurity firm Sophos.
Xuanye has not been mentioned before on hacker forums or other Telegram channels. Sophos added.
skip past newsletter promotionFree newsletter |Every weekday
Sign up to Business Today
Get set for the working day – we’ll point you to all the business news and analysis you need every morning

after newsletter promotion
Marijus Briedis, the chief technology officer at the online service provider NordVPN, said: “What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”
The potential hack comes after a string of British retailers including Marks & Spencer, the Co-op and Harrods suffered cyber incidents last year. M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean.