Two stories in the same news cycle point to the same pressure tactic. ATB was hit by a group calling itself DataSuckers, which reportedly demanded $400K, with 7.9M people said to be affected. Separately, UK fashion retailer Asos saw its shares fall 13% after a hack threat turned its own app into what the source describes as a de facto ransom note. The reporting calls this a near-identical tactic to the one DataSuckers used against ATB. Together, they show how ransomware gangs targeting consumer apps are putting pressure on companies through the channels customers see every day.
A note on what we know: the source material is brief. It confirms the headline figures above and names several of 2026's most active ransomware and extortion crews, including Qilin, Play, Safepay, Akira, and Scattered groups. It does not give a full technical account of either incident, so this post sticks to what has been reported.
What Happened at ATB and Asos
At ATB, the group DataSuckers reportedly demanded $400K. The scale of people reportedly affected, 7.9M, is far larger than the demand might suggest, which is a reminder that ransom figures and the number of exposed individuals are often unrelated.
At Asos, the effect showed up in the market. Shares dropped 13% after a hack threat, and the company's own app was reportedly used as the vehicle for the message, effectively working as a ransom note. The source does not detail what data, if any, was taken at Asos, so readers should treat the share drop as evidence of pressure rather than confirmation of a large breach.
How Extortion Crews Use Customer-Facing Apps as Leverage
Traditional ransomware locks systems and demands payment for a key. Many modern crews lean on a different lever: publicity. If a threat appears where customers and investors can see it, such as inside an app, the company faces reputational and financial damage whether or not the underlying attack was deep.
The logic is simple:
- Visibility creates urgency. A message in front of customers is hard to ignore or quietly manage.
- Markets react fast. The 13% Asos share drop shows how a threat alone can hit value.
- Customers become the audience. Pressure comes from users asking questions, not just from executives.
This is not unique to retail. Governments and industrial firms face similar demands, and some choose to hold the line. Berlin publicly declined a ransom in Berlin's refusal of a 30 Bitcoin ransom, and Stadler Rail did the same in its refusal of a $12.3M Everest demand. Those cases show that refusing is a real option, though each organization weighs it differently.
What Affected Users Should Watch For
If you have an account with a company named in a breach, or any company that has received an extortion threat, focus on practical steps rather than panic.
- Look for official notifications. Companies are generally expected to tell affected customers. Be cautious about messages that arrive first from unknown senders.
- Expect phishing. After a breach, scammers often impersonate the company, offering "account recovery" or "compensation" links. Go to the company's app or website directly instead of clicking.
- Watch for credential reuse risk. If a password from an affected account is used elsewhere, treat those other accounts as exposed.
- Monitor financial activity. Check statements for unfamiliar charges, especially if payment details were stored.
- Be skeptical of in-app messages that look unusual. If an app displays a strange demand or warning, do not follow instructions in it. Check the company's official channels.
What a VPN Can and Can't Do Here
A VPN encrypts your traffic between your device and the VPN server and can hide your IP address from sites you visit. That is useful on public Wi-Fi and for general privacy.
It does not help in a situation like this one. If a company's servers or databases are compromised, your data was exposed on their side, not in transit on your connection. A VPN cannot remove your information from a breached system, stop a criminal group from leaking it, or prevent phishing emails that use it. Think of it as one privacy tool, not a defense against corporate breaches.
What This Means For You
The practical takeaway is that your exposure often depends on decisions made by companies you have no control over. You cannot stop a crew like DataSuckers, but you can limit how much damage a leak does to you. Unique passwords, multi-factor authentication, and careful handling of unexpected messages matter far more than any single reaction to a headline.
It also helps to understand the wider context. Not every attacker is a profit-driven gang; some are state-linked, as Germany's data on foreign intelligence involvement in cyberattacks shows. Still, the extortion model aimed at consumer-facing brands is clearly active right now.
Actionable Takeaways
- Check breach notifications from any company you use, and confirm they are genuine by going to the official app or site.
- Rotate reused passwords. Start with email, banking, and shopping accounts, and use a password manager to generate unique ones.
- Enable multi-factor authentication wherever it is offered, preferably with an authenticator app rather than SMS.
- Treat unexpected messages with suspicion, including ones that appear inside apps.
- Read how organizations respond to demands. The Berlin and Stadler Rail cases linked above offer useful context on why some choose not to pay.
As ransomware gangs targeting consumer apps keep refining their pressure tactics, the best defense for individuals is steady, basic hygiene: know when your data may be exposed, secure your accounts, and verify before you click.




