ASOS Shares Plunge 9.6% After Hackers Hijack App Notifications
ASOS shares fell 9.56% after hackers hijacked its app notification system to broadcast ransom messages and direct users to a Telegram channel.
By Muhamed Porić
October 11, 2026 at 11:01 AM

ASOS shares fell sharply, closing down by 9.56% after hackers compromised the online fashion retailer's app notification system to broadcast ransom demands and direct users to an external Telegram channel.
The unauthorized push alert, titled "Asos hacked," reached consumer mobile devices before the company restricted access to the affected third-party communication platform. According to a Guardian report, the stock dropped as much as 13.2% during intraday trading before paring some losses.
"The unauthorised notification sent out to Asos customers has brought into the light how cyber incidents do not simply affect big business but can have repercussions for individuals much more widely too," said Dr Richard Horne, chief executive of the National Cyber Security Centre, in a statement regarding the incident.
Investigation and Corporate Response
ASOS stated that its core website and mobile application are operating normally with no current disruption to daily operations. The retailer apologized to customers for the security lapse, urging users to ignore the alert and avoid clicking any links.
"We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities," ASOS said in a statement.
While investigating the breach, ASOS noted that it maintains cybersecurity and business continuity insurance with a large global provider. However, the company emphasized that it remains too early to quantify any potential financial impact on trading.
Extortion Tactics and Threat Group Tactics
Responsibility for the breach was claimed by a previously lesser-known collective calling itself the Xuanye Group, which utilized the compromised notification pipeline to demand a ransom.
"It’s not unusual to see new groups emerge, and often they wait until they have what they see as a significant opportunity before they announce themselves so as to enter the ecosystem with ‘credibility’," said Aiden Sinnott, principal threat researcher at Sophos.
Security analysts warn that broadcasting demands directly to consumer devices represents an aggressive escalation in extortion methodology. By weaponizing customer-facing notifications, attackers aim to bypass traditional corporate communication channels and force executives into rapid negotiations.
"Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach," said Dray Agha, senior manager of security operations at Huntress.
Risks of Secondary Phishing Attacks
Cybersecurity researchers highlight that high-profile incidents frequently trigger a secondary wave of opportunistic fraud targeting anxious customers. Consumers are advised to exercise heightened caution regarding unexpected communications.
"High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund," said Marijus Briedis, chief technology officer at NordVPN.
Muhamed Porić
Founder and Editor of Embers.
Newsletter
Get Embers in your inbox
The stories that actually moved something, delivered when there's something worth sending, not daily filler.