ASOS has confirmed it is investigating a cyberattack after some customers received an unauthorised notification through the fashion retailer’s app on Tuesday morning.

The notification, sent at around 10:00 UK time, directed customers to a newly opened Telegram channel linked to a little-known cyber gang called the Xuanye group. The hackers claimed they had “fully compromised the Snowflake instance”, although the extent of their access has not been independently established.

ASOS said in a statement issued Tuesday afternoon that it was investigating “unauthorised activity involving third-party platforms” used to communicate with customers. The retailer said it had immediately restricted access to the affected notification platforms and was working with internal and external specialists and relevant authorities.

The company said basic personal information, including customers’ names and contact details, may have been accessed. It added that it does not believe payment-card information or account passwords were affected.

ASOS Shares Fall as Investors Assess Impact

ASOS’s website and app remained operational, with the company reporting no current disruption to its operations. It also said it was too early to quantify any potential impact on trading, while noting that it has cyber security insurance with a large global provider, including business continuity insurance.

ASOS

ASOS

The company’s shares fell more than 14% at one point on Tuesday and remained down more than 12% as investors assessed the potential longer-term consequences of the attack.

Cybersecurity experts warned that the incident could create both commercial and reputational risks. Marty Bauer of Omnisend said customers could begin questioning legitimate messages from ASOS after the retailer’s own notification channel was used to deliver a threat.

Marijus Briedis, technology chief at NordVPN, described the incident as unusually brazen because the alleged attackers appeared to use ASOS’s own app notification system to reach customers. He also warned that the publicity surrounding the incident could create opportunities for phishing attempts targeting customers.

Cavan Fabris, head of data and cyber at law firm RPC, said even a limited intrusion could develop into significant operational and reputational disruption. He stressed that the hackers’ claims should be treated as unverified until ASOS completes its investigation.

Why It Matters

The incident puts customer trust and digital communications at the centre of the breach. Even if payment and password information has not been affected, customers may need to be particularly cautious about messages claiming to come from ASOS while the investigation continues.