Shares in Asos tumbled by nearly 15 per cent on Tuesday after a phone alert sent from the company's mobile app told customers that the fashion retailer had been hacked.
The company admitted that customer data may have been stolen after app users received a notification on Tuesday morning with a message titled "ASOS HACKED".
The push alert read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
Asos later confirmed that it was "investigating unauthorised activity involving third-party platforms that we use to communicate with customers."
While basic personal details such as customer names and contact details appear to have been accessed, Asos stated that it did not believe payment information, payment-card details, or account passwords had been compromised.
Shares in the retailer fell by as much as 14.5 per cent on Tuesday before staging a mini-recovery to finish the trading day down close to 7 per cent.

Impact on business recovery and customer trust
The incident arrives at a difficult moment for the online fashion giant, which operates as one of the UK's largest e-commerce clothing platforms. Asos enjoyed booming sales during Covid-19 pandemic lockdowns, but has faced severe commercial pressures in recent years from falling consumer demand, rising operational costs, and intense competition from fast-fashion rivals such as Chinese competitor Shein.
Management has tried to stem the decline by clearing excess inventory and tightening its returns policy, including taking steps to ban certain customers from the platform. Prior to the cyber attack, there were signs that a financial turnaround was underway, with active customer numbers beginning to grow again following a major restructuring that involved selling off warehouses and discouraging product returns.
Even after Tuesday's share price drop, Asos stock remains up around 81 per cent over the past 12 months. However, the valuation remains down 83 per cent over a five-year period, leaving company leadership concerned about potential disruption to the brand's long-term recovery.
Dan Coatsworth, head of markets at investment broker AJ Bell, said the cyber incident had come "at a terrible time" because it was "happening so soon after positive signs of a business turnaround."
He cautioned that "the company risks losing customer trust if there is a sense that its systems aren't secure."
Coatsworth added: "While the cyber incident is still unfolding, Asos will be starkly aware of the risks of any hack to its business. It wasn't long ago that Marks & Spencer was knocked for six by a cyber-attack and that had a major negative impact on its earnings."
Comparing cyber attacks across the retail industry
A series of prominent UK household brands have fallen victim to cyber attacks in recent years, including retailer Marks & Spencer, luxury store Harrods, and automotive brand Jaguar Land Rover.
However, market analysts noted that security breaches vary significantly in scale and impact. John Stevenson, an analyst at City broker Peel Hunt, said the incident at Asos appears "very different" from the major cyber attack carried out against Marks & Spencer by teenage hackers last spring.
Stevenson said: "We don't know how far this has gone yet but based on the information we have at the moment it looks like a fairly basic data breach, it shouldn't impact its ability to trade."
By contrast, the previous hack at Marks & Spencer disrupted the majority of the retailer's operational systems, leaving customers unable to place online orders for several weeks. Stevenson noted that while Asos could experience "reputational" side effects if some customers feel "less secure than they did yesterday", he did not anticipate a "material impact" on the company's recovery.
Katie Cousins, equity research analyst at investment bank Shore Capital, added: "Asos has spent the last few years successfully fixing fundamental issues, and the strategy now is all about re-engaging the customer base and sustaining positive sales volumes, which it has made good initial progress on."
Security response and operational status
In a formal statement released on Tuesday, Asos outlined its response to the breach: "We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."
The company reiterated: "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted."
Asos confirmed that its core digital channels remain fully operational, stating: "Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate."
The retailer added that it holds cyber security insurance with a large global provider, which includes coverage for business continuity. However, Asos noted that it is currently too early to quantify any potential financial impact on trading.

