Asos says probing 'unauthorised activity' after phone alerts
UK online fashion giant Asos said Tuesday it was investigating "unauthorised activity involving third-party platforms" after its customers received a phone alert saying the retailer had been hacked.
Asos, which has 17 million active customers worldwide, said personal information like names and contact details "may have been accessed" but that it did not believe payment card information or account passwords were impacted.
The company noted its website and app were operating normally following the incident, which prompted its share price to slump initially by almost 15 percent in London.
Shares in the company had partially recovered by mid-afternoon but were still down Tuesday by nearly10 percent.
"We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers," Asos said in a statement.
"We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."
Customers had received a mobile app notification titled "Asos hacked" and directing them to a Telegram account.
"Dear Asos DPO and IT, we have fully compromised your Snowflake instance. Engage with us, or we will leak it," read the notification, according to screenshots shared on social media and reported by British media.
DPO stands for data protection officer, while Snowflake is a US company that provides its clients with a cloud-based platform for data storage, management and analysis.
In a statement shared with AFP, a Snowflake spokesperson said the firm began an investigation as soon as it became aware of the reported notification.
"At this time, we can report that we have found no compromise of the Snowflake platform," the statement added.
"We take customer privacy and security very seriously. The investigation is ongoing and we will provide further updates as soon as more information becomes available."
- 'Panic' aim -
This kind of notification, which amounts to "psychological warfare", is "designed to whip up panic", said Marie Wilcox, market strategy analyst at cybersecurity firm Binalyze.
The attackers reasoned that "any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response," she said.
Britain's state-run National Cyber Security Centre (NCSC) has offered Asos assistance, according to sources.
A spokesperson for the country's data watchdog, the Information Commission Office, said it did not appear "to have received a report on this matter at this stage".
Asos told shareholders it has cyber security insurance with a large provider and that it was "too early" to quantify any potential impact on its trading, Britain's Press Association news agency reported.
Founded in 2000, Asos generated £2.48 billion ($3.29 billion) in revenue while posting net losses of £298 million in the 12 months to the end of August 2025.
Its own brands account for 40 percent of the value of goods sold on the platform, compared to 60 percent for partner brands.
Last year, the UK was hit by a wave of cyberattacks targeting, among others, Jaguar Land Rover, Marks & Spencer, the department store Harrods and the Co-op food chain.
And three British airports belonging to the Manchester Airports Group were targeted by an attack in August that resulted in the theft of personal data belonging to 8.7 million customers.
Y.Walker--SMC