Meyka Pro banner
Global Market Insights

ASOS Stock Plunges 14% After Hackers Send Ransom Demand via App

October 6, 2026
09:01 PM
4 min read

Key Points

ASOS shares fell 14% after hackers sent ransom demand to millions of app users on October 6.

Names and contact details may have been accessed, but payment data and passwords were not compromised.

Stock recovered to 11% down after company confirmed cybersecurity insurance coverage.

Hackers used Snowflake cloud platform and directed customers to Telegram channel operated by group calling itself Xuanye Group.

Be the first to rate this article

ASOS.L shares plummeted 14% on October 6 after hackers sent thousands of UK app users a push notification claiming they had fully compromised the retailer’s data. The message, titled ‘ASOS hacked’, directed customers to a Telegram channel operated by a group calling itself Xuanye Group. ASOS said basic personal information including names and contact details may have been accessed, but payment card records and passwords were not compromised. The stock later recovered to around 11% down after the company confirmed it has cybersecurity insurance with a major global provider.

How the breach notification reached customers

At approximately 10:01 BST on October 6, ASOS app users across the UK received a pop-up message addressed to the retailer’s data protection officer and IT team. The message read: ‘Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.’ Snowflake is a cloud platform used to store, process and analyse customer data including transactions and demographic information such as clothing sizes and body measurements. It also enables push notifications to phones. The notification included a link to the hackers’ Telegram channel.

What data may have been accessed

ASOS said in a statement that basic personal information including name and contact details might have been accessed by an unidentified third party. However, the company stated that payment card records and passwords had not been compromised. The company added that it is too early to quantify any potential impact on trading. ASOS said its website and app are operating as normal with no current disruption to operations.

BBC Verify investigated the Telegram channel linked in the notification and found it was created on October 6. The channel’s first message read ‘hello dears’ before claiming it was a legitimate channel. A second message stated ‘Regarding ASOS, payment information is not affected.’ Four hours later, the channel posted that the app was safe to use and the incident involved customer information that was ‘safe on our server’ and would not be accessed for a ‘designated period’. BBC Verify found that Telegram channel and account names used spellings consistent with Chinese pinyin, a system for representing Chinese characters using the Latin alphabet. Messages also appeared to have been translated from Chinese, with the ‘hello dears’ greeting resembling the informal Chinese expression commonly used online.

Market reaction and insurance coverage

ASOS shares on the London Stock Exchange dived more than 14% immediately after the notification reached customers. The stock later recovered to about 11% down after ASOS said it has cybersecurity insurance with a large global provider, including business continuity insurance. The company said it took immediate action to restrict access to the notification platforms and is working with internal and external specialist advisers as well as all relevant authorities. Most cyber extortions are conducted privately, making this public notification to millions of customers an unusually aggressive tactic.

Final Thoughts

ASOS faces a critical test of customer trust after hackers weaponised its own app to demand a ransom. With payment data reportedly safe and cybersecurity insurance in place, the retailer’s ability to contain the breach and communicate clearly will determine whether the 11% stock loss becomes permanent.

FAQs

What data did the ASOS hackers access?

ASOS said basic personal information including names and contact details may have been accessed. Payment card records and passwords were not compromised.

Why did ASOS stock fall 14% on October 6?

Hackers sent thousands of UK customers a push notification claiming they had fully compromised ASOS data and demanding payment via Telegram.

Is the ASOS app safe to use now?

ASOS said its website and app are operating as normal with no current disruption. The company restricted access to notification platforms after the breach.

Who is the Xuanye Group?

An unidentified group that sent the ransom demand. BBC Verify found their Telegram channel used Chinese pinyin spelling and translated Chinese language patterns.

Disclaimer:

The content shared by Meyka AI PTY LTD is solely for research and informational purposes.  Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.

About Author

Author

Danny Kontos

Co Founder

Danny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.

What brings you to Meyka?

Pick what interests you most and we will get you started.

I'm here to read news

Find more articles like this one

I'm here to research stocks

Ask Meyka Analyst about any stock

I'm here to track my Portfolio

Get daily updates and alerts (coming March 2026)