NG Solution Team
Cybersecurity

ASOS shares fall 10% after hackers target customer information

ASOS shares fell 10% on Tuesday after the British online fashion retailer warned that some customer information may have been accessed following the unauthorised sending of a notification to shoppers.

The group said on Oct 6 it was investigating unauthorised activity involving third-party platforms it uses to communicate with customers, had taken immediate action to restrict access to those platforms and was working with internal and external specialist advisers as well as all relevant authorities.

“Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted,” the company said. ASOS added that its website and app were operating as normal, with no current disruption to operations.

ASOS says some customer data may have been accessed

The retailer said it has cyber insurance, including basic continuity insurance, but that it was too early to quantify any potential impact on trading. Shares in the group were up more than 60% so far this year, though they remain well below a peak in 2018. The company has been divesting assets and last month provided an upbeat profit forecast for fiscal 2026.

British companies and institutions have been increasingly hit by aggressive and regular cyber and ransomware attacks in recent years. The British Library, a blood testing service, the London Underground, Marks & Spencer, the Co-op and Jaguar Land Rover are among those that have suffered months of disruption due to such breaches.

Hackers claim Snowflake breach; Snowflake says platform not compromised

Notifications to ASOS shoppers, addressed to ASOS’ data protection officer and IT department, read, “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” A hacking group calling itself the “Xuanye group” claimed credit for compromising ASOS’ Snowflake repository in the push alert sent to users of the retailer’s app. The message included a link to a Telegram channel where the group said that payment information “is not affected,” and that the ASOS app “is safe to use.”

On the Telegram channel the group posted: “The incident involves customer information, it is safe on our server, and it will not be touched for a designated period.”

A spokesperson for Snowflake said it launched an investigation as soon as it became aware of the notification. “At this time, we can report that we have found no compromise of the Snowflake platform.” Hackers have previously targeted organisations’ Snowflake data repositories; in 2024 Google’s cybersecurity unit Mandiant detailed a widespread hacking spree targeting Snowflake data associated with at least 165 customers.

The retailer said it was continuing to investigate the incident and working with all relevant authorities and advisers.

Related posts

OpenAI models escaped sandbox and accessed Hugging Face systems

Jessica Williams

Was a JFrog zero-day exploited in the OpenAI–Hugging Face hack?

James Smith

Bitget Breach: $387.5M Stolen via Zero-Day in Third-Party Security

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy