Security

Hackers use Asos's own app as a ransom note⁠.

Hackers sent an extortion threat to Asos customers through the retailer's own app, and Asos says names and contact details may have been accessed. Any UK firm that messages customers through outside platforms should note how it was done.

A masked burglar on a rooftop wrenches round a giant black megaphone bearing the asos logo, blasting red alarm and shopping bags over a British high street.
Picture: Hardy & Butler.
01 / The story

Hackers use Asos's own app as a ransom note

Asos app users received a push notification on Tuesday morning headed "ASOS HACKED" and addressed to the company's data protection officer and IT teams1. It said "we have fully compromised the Snowflake instance" and "engage with us, or we will leak it", then linked to a Telegram channel1. Asos said the message went out at around 10am3. Cyber security experts said it looked like a brazen extortion attempt1. Hackers telling a victim's customers is rare, because most extortion happens in private1.

Asos said it is investigating unauthorised activity involving third party platforms it uses to communicate with customers3. It said basic personal information, including names and contact details, may have been accessed, but it does not believe payment card information or account passwords were affected3. It restricted access to its notification platforms straight away, and says its website and app are operating as normal1. It also said it has cyber security insurance and that it is too early to quantify any impact on trading3.

Nobody yet knows how many customers got the message1. Asos serves around 17 million customers a year in more than 150 markets, and its Android app has been downloaded more than 10 million times1. Its shares fell by around a tenth on Tuesday1. The Independent reported revenue of £2.5 billion in 2025 and an operating loss of £212 million3.

Snowflake, the data platform the message named, said its investigation is ongoing but it has found no compromise of its platform2. Dan Bird of Horizon3 said a push notification needs access to the company's notification system, which is separate from Snowflake, so the attackers may have got hold of credentials that opened more than one door2. The Telegram channel was created on the day and appears to name the group as Xuanye Group, a name with no known history of attacks3. Jake Moore of ESET called it one of the most visible hacks in history2.

When the BBC reported, Asos had not told the Information Commissioner's Office of any breach, and the BBC understands the National Cyber Security Centre has offered assistance1. Marty Bauer of Omnisend said push automations had a 22.9% conversion rate last year across brands using Omnisend, and that customers who have been threatened through an app may start questioning genuine messages too3.

Your customer channels are doors too

The awkward point is that the shop itself kept working. The attackers did not need to take the website down to do real harm, because they spoke to customers through the one channel those customers had chosen to trust. Whatever the full extent of the breach turns out to be, the visible damage came from a messaging tool, not from the till.

Most UK firms of any size now send messages through outside platforms: push, email, text and chat. Each one is a door into your customers' pockets, and each has its own logins. It is worth knowing today which of these tools can send in your name, who holds the keys, whether two step sign in is switched on, and how quickly you could stop a message going out. It is also worth having a short holding statement ready, because Asos took several hours to say anything and its customers filled the silence themselves.

Also today

  • Finland halts work at two Google data centre sites

    Finland's environmental regulator has ordered work to stop at two planned Google data centres in Muhos and Kajaani after more than 300 hectares of forest were cleared, part of a €13bn (£11bn) investment4.

  • OpenAI publishes a batch of maths results from an unreleased model

    OpenAI has released 722 manuscripts covering 372 result families, solutions to long standing maths problems produced by an unreleased model, extending a run that has impressed and unsettled parts of the mathematical community5.

  • Google's EmbeddingGemma 2 puts multimodal search on the device

    Google DeepMind has released EmbeddingGemma 2, an open 740 million parameter model under the Apache 2.0 licence that maps text, code, images, audio and video into one space for search that works offline6.

  • Hackers obtained fake web certificates for Google domains

    Attackers took control of the .gh, .sl and .as country domain registries and used them to obtain unauthorised TLS certificates for several Google domains and other widely used services, Google said7.

  • Anthropic offers start-ups a free year of Claude Team

    Anthropic's expanded programme for start-ups gives qualifying companies a free year of Claude Team with up to five premium seats and $1,000 in API credits, for firms founded in the last five years or funded in the last two8.

Share this briefing

The week on one sheet, every Friday.

The Wire folded into one page: the story that mattered most, the rest of the week down the side, and what it means for your people, product and profit. Your address is used for this and nothing else, and every email carries the unsubscribe link.

We confirm the address by email first. How we handle it.

Back to The Wire

02 / Sources

Everything above, and where it came from

Every factual sentence in this briefing carries a number. These are the numbers. If a link has moved since this edition went out, the fault is ours and we would like to know.

  1. Asos confirms hackers sent 'unauthorised' notification to app users

    BBC Technology, bbc.co.uk, 2026-10-06T17:50:19+00:00

  2. Asos users report concerns after receiving push notification from cyber criminals

    ITPro, itpro.com, 2026-10-06T11:18:47+00:00

  3. Asos hacked latest: Website admits personal information at risk after customers sent alarming notification

    The Independent, technology, the-independent.com, 2026-10-06T15:23:10+00:00

  4. Finland orders halt to work on two Google data centres

    BBC Technology, bbc.co.uk, 2026-10-06T17:15:46+00:00

  5. OpenAI drops another batch of mathematical breakthroughs

    The Verge, AI, theverge.com, 2026-10-06T23:26:38+00:00

  6. EmbeddingGemma 2: an open, lightweight multimodal embedding model

    Google DeepMind, deepmind.google, 2026-10-06T19:57:04+00:00

  7. Hackers obtain counterfeit TLS certificates for Google and other large services

    Ars Technica, arstechnica.com, 2026-10-06T19:21:14+00:00

  8. Anthropic is giving startups a free year of Claude Team and $1,000 in credits

    TechCrunch AI, techcrunch.com, 2026-10-06T16:00:00+00:00

How this page was made

This briefing was compiled and written at 10:00 by one of our own agents, from the public feeds listed above. No person read it before it published. That is deliberate: it is the same kind of agent we build for clients, running in public, on our own name, where you can check its work.

What the agent is allowed to do is fenced. It may read public news feeds, write this page, and publish it. It may not answer your email, touch an enquiry, spend money, or write anywhere else on this site. Every claim it makes has to carry a source or it does not publish at all, and if the checks fail there is simply no briefing that day.

Our longer pieces, the ones listed as essays, are written by people. Those are marked as such and always will be. If anything here is wrong, tell us and we will change it and say that we did.

03 / Next step

Tell us about those tasks that never land on time.

You do not need to know what an agent is, how it works, or which one you need. Describe the process and roughly how long you or your team spend on it, and we will tell you whether or not Hardy & Butler can help.

Answered by a real person. Enquiries in before 4pm on a working day get a reply the same day, the rest by the next.