Man Shot His Mother Seven Times After Smoking a THC Vape

Inset: Jamie Lee Voelker (Windom Police Department). Background: The two streets in Windom, Minnesota, where Voelker committed the crimes (Google Maps). A Minnesota man has...
HomeNewsASOS Customers Receive Threatening Messages Amid Suspected Hack

ASOS Customers Receive Threatening Messages Amid Suspected Hack

Asos appears to have suffered a cyberattack after customers received a striking warning that their personal data could be published.

The alert, delivered through the online fashion retailer’s app today under the heading “ASOS hacked”, said: “Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it: t.me/xuanyewengateway.”

DPO is short for data protection officer, the person responsible for overseeing the security of customers’ information.

Snowflake is a cloud-based platform used to store, manage and analyse data. The system can hold customer information including behavioural, transactional and demographic records.

The notification directed recipients to a Telegram channel linked to the alleged attackers, known as the Xuanye group gateway. The channel appears to have been created today.

Cybersecurity specialists described the message as an “unusually brazen” act of psychological warfare, apparently intended to trigger panic and pressure the company into responding quickly.

The Daily Mail has contacted Asos for comment.

Asos, which owns brands including Topshop and Miss Selfridge, says it serves 17 million customers across 150 countries. Its website and app appeared to remain operational despite the suspected breach.

The company’s shares dropped by 11 per cent after reports of the alleged hack emerged.

Customers reacted with alarm online, describing the alert as a “crazy notification”. Some said they had “never deleted my payment methods so quick”.

Asos appears to have been hacked after customers received a message threatening to leak their data

Asos appears to have been hacked after customers received a warning that their data could be leaked

Asos says it has 17 million customers in 150 countries. Its website and app appear to be working still despite the apparent breach

Asos says it has 17 million customers in 150 countries. Its website and app appeared to remain operational despite the suspected breach

Marie Wilcox, vice president of market strategy at cybersecurity company Binalyze, said the alert was “psychological warfare” intended to provoke panic. “Attackers know that any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response,” she said.

Marijus Briedis, chief technology officer at NordVPN, called the message “an unusually brazen and threatening” communication.

“The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained,” he said.

If the hackers’ claims prove accurate, Mr Briedis said the central issue will be determining what data was stored in the Snowflake environment and whether it was accessed or copied.

However, he stressed that customers should not yet conclude their personal or payment information has been stolen. “That hasn’t been established,” he said.

“What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.

“Criminals may exploit the publicity by sending emails and texts pretending to be from ASOS. These could ask customers to reset a password, verify payment information, review an order or request a refund.”

He added that the incident highlighted the risks of attackers gaining access to a trusted company communication channel. If criminals can potentially contact customers through a retailer’s own systems, he said, their claims become far more convincing and the potential damage increases significantly.

Dr Pete Membrey, the chief research officer at ExpressVPN, said the worst thing people can do is panic.

‘Getting a message like that from an app you trust is genuinely unsettling,’ he said. 

‘Most people think of a hack as something that happens out of sight, so seeing a threat land on your own phone makes it feel much more personal.’

Dr Membrey advised Asos customers to do ‘some simple due diligence. Don’t tap on the notification or follow the link in it. Go to the Asos website directly, by typing in the address yourself rather than through an email or the app, and reset your password.’ 

Kamran Bahdur, chief information officer at cybersecurity firm FLR Spectron, advised Asos customers to change their passwords ‘for an extra layer of protection and peace of mind’. 

He said: ‘This should be taken seriously and treated as a potential extortion attempt until we’ve verified the facts.’ 

Cyber security expert Jake Moore described it as ‘one of the most visible hacks in history’ and could ‘put a lot of customer data at risk’. 

‘By broadcasting their breach directly to Asos app users, the threat actors are likely trying to apply pressure to Asos, showing how extensive their access is so they can leverage some sort of ransom,’ the global cyber security adviser at ESET told the Independent. 

He said the fact hackers had sent the message through Asos’s app suggests they had gained access to some of the firm’s systems. 

But Mr Moore said it doesn’t ‘prove their full claims about the extent of the data breach’. 

Charlotte Wilson, head of enterprise at cyber-security firm Check Point, told the BBC: ‘If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note.’ 

Britain is Asos’s largest market, representing 49 per cent of all revenues in the first half of the latest financial year.

The fast-fashion firm is undergoing a major turnaround programme to halt declining sales and return to profit.

Mike Ashley’s Frasers Group owns 29.26 per cent of Asos and is the firm’s largest shareholder. 

Britain has been hit by several cyber attacks in recent months. In August, up to 1,000 charities, including Breast Cancer UK, English National Ballet and the Molly Rose Foundation, were targeted. 

Criminals targeted Beacon CRM, which provides customer management software to the charity sector.

It is thought the firm mistakenly published an access key online that allowed hackers to copy its databases.

Meanwhile, M&S and Co-op were left crippled by a cyberattack in the spring and summer of 2025. 

Notorious hacker group Scattered Spider was linked to the attack that left shelves empty for weeks and forced M&S to stop accepting all online orders and payments.

Have YOU been affected? Email matt.strudwick@dailymail.co.uk