Asos, the UK-based online fashion retailer, disclosed on Wednesday that it is investigating a potential data breach after thousands of its customers received an unauthorized push notification claiming the company had been hacked. The message, sent via the Asos mobile app, instructed the company’s data protection and IT teams to engage with the alleged hackers or face the public release of compromised information. The notification included a link to a Telegram account associated with a group identifying themselves as Xuanye.

The alert read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” referring to Snowflake, a US-based cloud data storage service used by Asos and other major companies. The hackers claimed that payment information had not been affected and that customer data remained secure on their servers for a designated period. Xuanye has reportedly set a two-week deadline for Asos to respond to their demands, although the ransom amount and specific data accessed were not disclosed.

Asos confirmed that "basic personal information, including names and contact details, may have been accessed" but stated it does not believe payment card details or passwords were compromised. The company emphasized that its website and app were still functioning normally and urged customers not to engage with the unauthorized notification or external links it contained.

Snowflake denied any breach of its platform but said it was investigating the incident. Industry experts noted that sending push notifications requires access to Asos's app communication systems, which are separate from Snowflake’s data services, suggesting multiple attack points might be involved. Cybersecurity specialists warned customers to remain vigilant for potential phishing attempts exploiting the incident.

The incident has unsettled investors, with Asos’s shares dropping as much as 14 percent during trading, wiping nearly £60 million off the company’s market value, before closing down 9.6 percent at 454 pence. The company has delayed detailed public comment pending a fuller investigation but reassured stakeholders that it holds insurance coverage with a major global provider.

The emergence of Xuanye group is notable, as the name has not previously been associated with known hacking collectives. Their tactics—publicly demanding ransom via customer-targeted alerts—are considered unusually brazen by cybersecurity experts.

Asos, which owns brands such as Topshop and Miss Selfridge, serves around 17 million customers worldwide with approximately half of its revenue coming from the UK. The retailer has been in the midst of a challenging turnaround under Chief Executive José Antonio Ramos Calamonte, facing intense competition from fast-fashion operators like Shein and Temu, as well as financial pressures and shifts in consumer demand. The company’s largest shareholder is Mike Ashley’s Frasers Group, holding nearly a 29 percent stake.

This incident follows a spate of cyberattacks on UK retailers in recent years, including notable breaches at Marks & Spencer, the Co-op, and Jaguar Land Rover, which have caused significant operational disruptions and financial losses. Asos’s ability to manage this situation will be closely watched by investors and customers alike, given the potential implications for its ongoing recovery efforts.