Asos shares fall 13% after customers receive apparent hacking message

by Girls Rock Investing

Shares of Asos fell more than 13% on Tuesday after customers of the British online fashion retailer received push notifications appearing to claim that the company had been hacked.

Users across the UK reported receiving pop-up messages through the Asos app that appeared to have been sent by hackers attempting to extort the retailer.

The notification, addressed to Asos’ data protection officer and IT department, reportedly read: “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

Dozens of users posted the message on social media, saying they were confused about its meaning and why it had been delivered directly through the retailer’s app.

The website and app continued to operate on Tuesday morning, while Asos was understood to be investigating whether a cyberattack had actually taken place.

The message included a link directing customers to a Telegram channel operated by an apparent cyber gang calling itself the Xuanye group.

Cybersecurity researchers said they had not previously heard of the group, raising the possibility that the notification could also be an attempt to attract attention or establish credibility.

“It’s not unusual to see new groups emerge, and often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with ‘credibility’, ” said Aiden Sinnot, principal threat researcher at cybersecurity firm Sophos.

Snowflake connection raises concerns

The reference to Snowflake has added to concerns surrounding the alleged incident.

Snowflake is a cloud platform used by companies to store, process and analyse data, including transaction information and customer demographics such as clothing sizes and body measurements.

The platform can also support services such as push notifications to customers’ phones.

“Snowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim,” said Dray Agha, senior manager of security operations at cybersecurity platform Huntress.

Snowflake shares were down 0.4% in premarket trading on Tuesday.

Snowflake has faced scrutiny over data breaches involving customers in recent years, including an attack on Ticketmaster in which customer information was reportedly stolen.

However, security experts cautioned that the claims made through the Asos notification should not be treated as confirmation that the retailer’s Snowflake environment had been compromised.

Tatyana Shishkova, lead security researcher at cybersecurity firm Kaspersky, said organisations needed to establish which systems had been accessed, what information may have been exposed and how attackers gained entry through a forensic investigation.

“The ability of hackers to directly contact potential victims through push notifications in the Asos app highlights how disruptive cyber incidents can be when threat actors gain access to trusted communication channels,” Shishkova said.

She added that such incidents could damage customer confidence when alarming messages appeared to originate from a legitimate company.

UK companies face growing cyber threats

The incident comes amid a series of high-profile cyberattacks affecting British businesses and institutions.

The British Library, a blood-testing service, the London Underground, Marks & Spencer, Co-op and Jaguar Land Rover have all suffered cyber incidents in recent years, with some resulting in prolonged disruption.

Shishkova said the Asos episode also demonstrated the importance of robust identity and access controls across cloud environments.

“Regardless of the attack path, the incident reinforces the importance of strong identity and access management across cloud environments,” she said.

Recent Kaspersky investigations have found that cybercriminals increasingly exploit misconfigurations, exposed services and legitimate tools already available within organisations rather than relying exclusively on sophisticated malware.

In some cases, attackers have also abused trusted corporate systems to deliver ransom demands directly to employees and increase the psychological pressure surrounding an attack.

For Asos, the immediate question remains whether the notification represents a genuine compromise of company systems or an attempt to create panic around an unverified claim.

The London-headquartered retailer, which owns brands including Topshop and Miss Selfridge, has 17 million customers across more than 150 countries and employs about 2,800 people.

The UK is its largest market, accounting for 49% of group revenue in its first-half results.

Its stock is up over 50% despite Tuesday’s decline.

The post Asos shares fall 13% after customers receive apparent hacking message appeared first on Invezz

You may also like