Asos fell 13% after hackers turned its own app into an extortion billboard
A ransom note pushed to shoppers' phones knocked about £70 million off Asos and 3% off Snowflake before anyone verified a word. Asos now says customer names and contact details may have been accessed, and UK law puts the regulator on a 72-hour clock.
Vincent Jiang · 3 min read
A ransom note, delivered by the victim's own app
At around 10am on October 6, phones running the Asos app lit up with a message addressed to the retailer's data protection officer and IT staff: "We have fully compromised the Snowflake instance. Engage with us, or we will leak it." 1 2 The note linked to a Telegram channel created that same morning by a group calling itself Xuanye. 1 3
Asos fell as much as 13.2% and closed 9.56% lower, its steepest one-day move since September 2025, taking roughly £70 million off its market value at the low. 1 2 4 5 Snowflake, whose product was named in the note, slipped as much as 3.2% in premarket trading and about 2% in New York. 2 6
Asos paid four times what Snowflake did for a claim no one has verified
Data
| Value | |
|---|---|
| Asos: intraday low | -13.2% |
| Asos: close | -9.56% |
| Snowflake: premarket | -3.2% |
| Snowflake: NY morning | -2% |
Asos admits the pipe, not the data
More than five hours after the notification, Asos confirmed "unauthorised activity involving third-party platforms that we use to communicate with customers", said names and contact details "may have been accessed", and said it did not believe payment-card data or passwords were impacted. 4 7 Snowflake opened its own investigation and reported "no compromise of the Snowflake platform". 8 9 7
The headline claim remains unproven on every side: Xuanye has published no sample of the alleged data 8, Sophos says the group had never appeared on the forums or channels it monitors 4, and the BBC could not even confirm Asos is a Snowflake customer 3. What the message does prove is a breach of the notification pipe itself. "Sending a ransom demand directly to consumer devices is an aggressive extortion tactic," said Dray Agha of Huntress. 2 4
A 72-hour clock runs against the Christmas peak
If this counts as a notifiable breach, Asos has 72 hours from awareness to tell the Information Commissioner's Office, on pain of fines up to £8.7 million or 2% of global turnover. 10 The timing bites: the shares were up more than 60% this year, Asos issued an upbeat fiscal 2026 profit forecast in September, and it carries 16.4 million active customers into peak trading. 7 2 The company holds cyber and business-continuity insurance and says it is "too early to quantify any potential impact on trading". 4
Britain's recent record is the risk being priced: Marks & Spencer shut its website for weeks after last year's attack, with the Co-op, Harrods and Jaguar Land Rover hit in the same wave. 4 2
Snowflake pays for a breach it says never happened
The 2024 comparison rhymes: at least 165 Snowflake customers, Ticketmaster and AT&T among them, were robbed through stolen credentials, not through any flaw in the platform. 8 7 Every customer-side extortion that names Snowflake now moves its stock, a contagion the platform carries but never invoices. 6
If both of Tuesday's claims hold, the attackers "got hold of credentials that opened more than one door", said Dan Bird of Horizon3. 5 Two clocks are running: the ICO's 72 hours, and Xuanye's promise that the data "will not be touched for a designated period". 4 One of them expires first.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



