ASOS Hacked? What Happened & How Customers Can Stay Safe

Picture of Team Next Gen
Team Next Gen
Share it:

A shocking “ASOS HACKED” notification appeared on the phones of ASOS customers on 6 October 2026, turning what initially looked like a routine shopping notification into a major cybersecurity story.

The message claimed that attackers had “fully compromised” an ASOS Snowflake instance and threatened to leak data unless the company engaged with them. It also directed recipients towards an external Telegram channel.

ASOS has since confirmed that an unauthorised notification was sent to customers and that it is investigating unauthorised activity involving third-party platforms used to communicate with customers.

The company says that basic personal information, including names and contact details, may have been accessed, but it does not currently believe that payment-card information or account passwords were affected.

However, there is an important distinction between what has been confirmed and what the attackers claimed.

At the time of writing, there is no public evidence proving that the entire ASOS customer database was stolen or that Snowflake itself was compromised. Cybersecurity researchers cited by Cybernews said they had not found leaked files or samples demonstrating that attackers possess ASOS customer records.

That makes this incident particularly important.

It is not simply a story about whether a database was stolen. It raises bigger questions about third-party platforms, cloud security, identity management, customer communications and how attackers can exploit trusted digital channels.

What Happened to ASOS?

On Tuesday 6 October, some ASOS customers received an unexpected push notification through the ASOS app.

The notification was titled:

“ASOS HACKED”

It was addressed to the ASOS Data Protection Officer and IT team and claimed that attackers had compromised a Snowflake environment and would leak information unless ASOS engaged with them.

The message also included a link appearing to direct users towards a Telegram channel associated with an identity calling itself Xuanye Group.

The unusual part was not simply the content of the message.

The notification appeared to have been delivered through a trusted ASOS customer communication channel.

That meant customers were seeing a cybersecurity threat directly through an application they already trusted.

ASOS subsequently confirmed that an unauthorised notification had been sent and said it had taken immediate action to restrict access to the affected notification platforms.

Was ASOS Actually Hacked?

The short answer is: ASOS has confirmed unauthorised activity, but the full extent of the compromise is still being investigated.

There are several different claims involved.

What is confirmed?

ASOS has confirmed:

  • An unauthorised push notification was sent to customers.
  • The incident involved third-party platforms used to communicate with customers.
  • Names and contact details may have been accessed.
  • Access to affected notification platforms has been restricted.
  • ASOS is working with specialist advisers and relevant authorities.
  • The company does not currently believe payment-card information or account passwords were affected.
What is claimed but not proven?

The attackers claimed that they had completely compromised an ASOS Snowflake instance and threatened to leak data.

However, that claim has not been independently demonstrated publicly.

Cybernews reported that security researchers had found no leaked files or data samples proving that the attackers possess ASOS customer records. Researchers also found no confirmation that Snowflake itself had been compromised.

This distinction is critical.

A ransom message is not, by itself, proof of the amount of data stolen.

Did Hackers Steal ASOS Customer Data?

ASOS says that basic personal information, including names and contact details, may have been accessed.

However, there is currently no confirmed public evidence that the attackers obtained the entire ASOS customer database.

The UK National Cyber Security Centre has advised ASOS customers to assume they may be affected, even if they did not receive the unauthorised notification.

The situation should therefore be understood as:

Confirmed: unauthorised access/activity occurred.

Potential: names and contact details may have been accessed.

Not currently established: that the complete customer database was stolen.

Not currently believed by ASOS: payment-card information and account passwords were affected.

This is why customers should remain cautious without assuming that every piece of their personal information has been leaked.

What Is Snowflake and Why Was It Mentioned?

Snowflake is a cloud-based data platform used by organisations to store, process and analyse data.

The ASOS notification specifically claimed that a Snowflake instance had been compromised.

However, security experts have pointed out an important technical issue: the system used to send push notifications and the data environment referred to in the attackers’ message are not necessarily the same system.

Cybernews cited experts who suggested that if the attackers genuinely accessed multiple systems, the incident could potentially involve compromised credentials or access that crossed more than one connected environment.

LinkedIn News also highlighted this distinction.

Cybersecurity professionals discussing the incident pointed out that modern businesses rely on interconnected systems including cloud platforms, identity providers, APIs, notification services, CRM platforms and data environments.

That means attackers do not necessarily need to break through a company’s traditional network perimeter if they can obtain valid credentials to a privileged cloud or third-party account.

Why the ASOS Notification Was So Concerning

Most cyber attacks happen quietly.

Customers may never know that a criminal has accessed a system until a company announces a breach.

The ASOS incident was different.

The attacker appears to have gained enough access to a trusted customer communication mechanism to send a message directly to users.

That creates a completely different psychological effect.

Instead of reading about a possible cyber attack later on social media or in the news, customers themselves suddenly received a notification through the official ASOS app.

This is one reason cybersecurity professionals described the incident as unusually visible. IT Pro quoted ESET Global Cybersecurity Adviser Jake Moore as saying that the incident ranks among the most visible cybersecurity incidents in recent memory, while noting that the notification does not itself prove the attackers’ full claims.

What Cybersecurity Experts Are Saying

The expert reaction on LinkedIn highlights several important lessons.

One recurring point is that cloud security and identity security are now just as important as traditional network security.

Alexander Tzafos, commenting through LinkedIn News, highlighted the importance of multi-factor authentication, least-privilege access, removing unused accounts, monitoring suspicious sign-ins and regularly reviewing privileged accounts.

Other LinkedIn discussions focused on the architecture behind modern e-commerce platforms.

A retailer such as ASOS can have a complex ecosystem involving:

  • Customer-facing websites
  • Mobile applications
  • APIs
  • CRM systems
  • Marketing platforms
  • Payment systems
  • Order management
  • Analytics
  • Cloud data platforms
  • Push notification services
  • Third-party suppliers

The important security question is therefore no longer simply:

“Is our website secure?”

It is:

“How secure is every account, platform, integration and identity connected to our business?”

That is a much bigger challenge.

What Is the Biggest Risk for Customers?

For most customers, the immediate concern should be phishing and social engineering.

Even if payment-card information and passwords were not accessed, exposed names and contact details can still have value to criminals.

An attacker could potentially use customer information to create more convincing messages.

For example:

“Your ASOS account has been affected by the recent security incident. Click here to secure your account.”

The message may contain the customer’s real name and appear to come from a legitimate support team.

That makes it much harder to distinguish from a genuine communication.

Cybernews security experts warned that attackers could use customer information to make future scams more convincing, even if the original incident does not ultimately prove to be a full database breach.

What Should ASOS Customers Do Now?

The first rule is simple:

Do not panic.

And, more importantly:

Do not click suspicious links.

ASOS has specifically instructed customers to disregard the unauthorised notification and not click or engage with the external link included in it.

Customers should also take the following steps.

1. Access ASOS Directly

If you need to check an order, account or notification, open the ASOS website or app directly.

Do not use links contained in unexpected messages.

2. Watch for Follow-Up Scams

Be particularly careful over the coming days and weeks.

Scammers may use the ASOS incident itself as a reason to contact customers.

Messages could mention:

  • Account security
  • Refunds
  • Orders
  • Payment verification
  • Password resets
  • Data breach compensation
  • Customer support

Treat unexpected requests with suspicion.

3. Do Not Provide Passwords or Payment Details

ASOS will not require you to provide your password through an unexpected message.

Never share:

  • Passwords
  • One-time verification codes
  • Bank details
  • Card numbers
  • PINs

with someone who contacts you unexpectedly.

4. Review Your ASOS Account

Check for anything unusual, including:

  • Changes to your account
  • Unknown activity
  • Unexpected orders
  • Changes to account details

The NCSC specifically recommends reviewing account activity following an incident of this nature.

5. Protect Reused Passwords

ASOS currently says it does not believe account passwords were affected.

However, if you use the same password on ASOS and other websites, that creates an avoidable risk.

Use a unique password for every important account.

6. Enable Strong Authentication

Where available, use:

  • Passkeys
  • Two-step verification
  • Multi-factor authentication

The NCSC recommends passkeys or strong, separate passwords combined with two-step verification.

7. Monitor Your Bank Account

ASOS does not currently believe payment-card information was affected.

Nevertheless, customers should continue monitoring their financial accounts and report any transactions they do not recognise.

Cybernews also recommends contacting your bank immediately if you notice unauthorised transactions.

Should ASOS Customers Change Their Password?

ASOS is not currently asking customers to change their ASOS password.

The company says it does not believe account passwords were impacted.

That does not mean customers should ignore password security.

If you have reused your ASOS password elsewhere, particularly on an email account or another shopping platform, changing the reused password is sensible.

Email accounts deserve particular attention because access to an email account can potentially allow criminals to reset passwords for other services.

Could This Lead to Identity Theft?

Potentially, but it is too early to say that ASOS customers are facing widespread identity theft as a result of this incident.

Names and contact details alone do not necessarily provide enough information to take over someone’s identity.

The greater immediate concern is that these details could be combined with information obtained from other sources.

For example, criminals may already know:

  • A person’s name
  • Email address
  • Telephone number
  • Approximate location
  • Shopping interests
  • Previous data exposed elsewhere

Combining separate pieces of information can make a scam significantly more convincing.

This is why even relatively basic personal data deserves protection.

How Do You Know a Message Is Really From ASOS?

This is particularly important after a high-profile incident.

ASOS itself warns customers that scammers impersonate the company through social media, fake Gmail accounts, WhatsApp and fake websites.

ASOS advises customers to rely on ASOS-branded email addresses, verified social media accounts and its official website when interacting with the company.

If someone contacts you claiming to be ASOS support and asks you to:

  • Click a strange link
  • Move the conversation to Telegram or WhatsApp
  • Provide your password
  • Share a verification code
  • Send payment information

stop and verify the request through an official ASOS channel.

Why Businesses Should Be Paying Attention

For businesses, the ASOS incident is bigger than one retailer.

It demonstrates how a cyber incident can move rapidly from a technical problem into a customer, reputation and business continuity problem.

A compromised system does not have to contain credit-card information to cause serious disruption.

If an attacker can control a trusted customer communication channel, they may be able to:

  • Send false messages
  • Damage customer trust
  • Create panic
  • Trigger media coverage
  • Increase customer support demand
  • Affect investor confidence
  • Damage the company’s reputation

In the ASOS case, the notification itself became part of the public incident.

Third-Party Risk Problem

ASOS has said the incident involved third-party platforms used to communicate with customers.

That should be a major warning for businesses of all sizes.

Many organisations rely on external platforms for:

  • Email marketing
  • SMS
  • Push notifications
  • CRM
  • Cloud storage
  • Analytics
  • Customer support
  • Payment processing
  • Social media management
  • AI tools
  • Data processing

The business may not own the infrastructure, but it still carries responsibility for understanding the risks created by those connections.

A company can have excellent internal security and still be exposed through a poorly protected third-party account.

The Identity Security Lesson

One of the strongest lessons from the expert reaction to the ASOS incident is that cybersecurity is increasingly becoming an identity problem.

Attackers do not always need to exploit a technical vulnerability.

Sometimes they need:

A username + password + insufficient authentication + excessive permissions.

If a compromised account has access to multiple systems, one stolen identity can potentially become a gateway into a much wider environment.

This is why businesses should review:

  • MFA
  • Privileged accounts
  • Admin permissions
  • SSO
  • API keys
  • Service accounts
  • Unused accounts
  • Third-party access
  • Password policies
  • Login monitoring

What Businesses Can Learn From ASOS

1. Secure the Entire Digital Ecosystem

Do not focus only on the main website.

Review every system connected to the business.

2. Use Multi-Factor Authentication

MFA should be enabled on critical accounts, particularly administrator and cloud accounts.

3. Apply Least Privilege

Employees and suppliers should only have the access they genuinely need.

If an account is compromised, limiting its permissions can significantly reduce the potential damage.

4. Review Third-Party Access

Maintain a clear record of:

  • Who has access
  • What they can access
  • Why they have access
  • When access was last reviewed

Remove unnecessary permissions.

5. Protect Cloud Environments

Cloud platforms should receive the same security attention as traditional infrastructure.

Security teams should monitor:

  • Privileged access
  • Unusual logins
  • API activity
  • Data exports
  • Permission changes
  • Authentication anomalies
6. Secure Communication Platforms

Customer communication systems can be just as sensitive as databases.

A notification system may have the ability to reach millions of people.

That makes it a valuable target.

7. Monitor Connected Systems

Businesses should be able to detect unusual activity quickly.

If a platform suddenly sends an unusual notification, changes configuration or generates unexpected API activity, someone needs to know.

8. Have an Incident Response Plan

A business should know what happens in the first hour of a cyber incident.

Who:

  • Investigates?
  • Restricts access?
  • Contacts suppliers?
  • Communicates with customers?
  • Handles regulators?
  • Manages media?
  • Updates employees?

Without a clear plan, valuable time can be lost.

Cybersecurity Is No Longer Just an IT Problem

The ASOS incident demonstrates how quickly cybersecurity can become a business-wide issue.

A single incident can affect:

Customers

They may face phishing, fraud and privacy concerns.

Employees

Teams may need to manage a sudden increase in customer enquiries and operational disruption.

Management

Senior leadership must make rapid decisions under uncertainty.

Reputation

Customers may question whether the company can protect their information.

Investors

Markets may react to uncertainty around operational and financial consequences.

Legal and regulatory teams

Businesses may need to assess reporting and data-protection obligations.

Cybersecurity therefore belongs at board level, not just inside the IT department.

The Financial and Reputation Impact

The cost of a cyber incident can extend well beyond the cost of repairing compromised systems.

Businesses may face:

  • Incident-response costs
  • Forensic investigations
  • Legal costs
  • Customer support costs
  • Technology remediation
  • Lost productivity
  • Business interruption
  • Regulatory exposure
  • Reputational damage
  • Customer churn
  • Investor concerns

The market reaction can also be significant.

ASOS shares fell sharply after the incident became public, illustrating how cybersecurity events can quickly become financial and investor-confidence issues as well as technical problems.

It is important, however, not to assume that the share-price movement represents the final financial impact of the incident.

ASOS has said it is still investigating and that the full consequences remain under assessment.

Why the ASOS Incident Is Different

There have been many major data breaches.

What makes this incident particularly unusual is how visible the alleged compromise became.

Instead of an attacker simply stealing data and demanding payment privately, customers themselves became part of the attack narrative.

The company’s own communication channel was allegedly used to deliver the threat.

That creates a powerful lesson:

Your customer communication infrastructure is part of your security perimeter.

If customers trust a notification because it appears inside an official app, compromising that channel can give an attacker something extremely valuable: credibility.

What Businesses Should Ask Themselves

The ASOS incident should encourage businesses to ask some uncomfortable questions.

If our email platform was compromised, could an attacker contact our customers?

If our CRM account was compromised, what customer data could be accessed?

If an administrator’s credentials were stolen, how many systems could they reach?

Can we immediately revoke third-party access?

Do we know every platform connected to our customer data?

Are our cloud accounts protected with MFA?

Do we monitor privileged logins?

Can we detect unusual API activity?

Do we have an incident-response plan?

Could we communicate with customers safely if our normal communication systems were compromised?

These questions are relevant to a global retailer, but they are equally relevant to a small UK business.

What Happens Next?

ASOS continues to investigate the incident.

The company has restricted access to the affected notification platforms and is working with specialist advisers and relevant authorities.

The NCSC has advised ASOS customers to assume they may be affected and to remain alert for suspicious messages.

At present, the precise scope of the incident remains unclear.

There is a significant difference between:

“An attacker claims they stole everything”

and

“Investigators have confirmed that everything was stolen.”

Those statements should not be treated as equivalent.

The responsible approach is to separate confirmed facts from unverified claims while taking sensible precautions.

Frequently Asked Questions

Was ASOS hacked?

ASOS has confirmed unauthorised activity involving third-party platforms used to communicate with customers. The full technical scope of the incident remains under investigation.

Did hackers steal ASOS customer data?

ASOS says basic personal information, including names and contact details, may have been accessed. There is currently no public confirmation that the entire ASOS customer database was stolen.

Was Snowflake hacked?

The attackers claimed that they had compromised an ASOS Snowflake instance. However, there is currently no public evidence confirming that Snowflake itself was compromised in this incident.

Were ASOS passwords exposed?

ASOS says it does not believe account passwords were affected.

Was payment information stolen?

ASOS says it does not believe payment-card information was impacted.

Should ASOS customers change their passwords?

ASOS is not currently asking customers to change their passwords. However, anyone who has reused their ASOS password elsewhere should consider changing the reused password.

Should customers be worried about phishing?

Yes. Phishing and impersonation attempts are an important risk following a high-profile incident, particularly where names and contact details may have been accessed.

What should I do if I receive another ASOS message?

Do not click suspicious links or provide personal information. Access ASOS directly through its official website or app and verify any communication through official customer-support channels.

Is it safe to continue shopping on ASOS?

ASOS says its website and app remain available and that customers can continue shopping normally.

What can businesses learn from the ASOS incident?

The main lessons include stronger identity security, MFA, least-privilege access, third-party risk management, cloud security, monitoring, incident response and secure customer communications.

Conclusion

The ASOS cyber incident is still developing, and some of the most serious claims made by the attackers remain unverified.

What is already clear, however, is that an unauthorised party gained access to a system involved in customer communications and was able to send a message through a trusted channel.

For customers, the priority is straightforward:

Stay alert. Avoid suspicious links. Watch for follow-up scams. Protect reused passwords. Monitor your accounts.

For businesses, the lesson is much bigger.

Security cannot stop at the website, firewall or office network.

Modern organisations depend on a web of cloud platforms, identities, APIs, third-party providers, communication tools and data systems.

Every connection creates another potential route into the organisation.

The ASOS incident is therefore a timely reminder that cybersecurity is not simply about stopping someone from stealing data.

It is also about protecting the systems that customers trust.

When an attacker can turn a trusted communication channel into a public ransom note, the consequences can extend far beyond the original technical compromise.

For businesses of every size, the question is no longer simply:

“Are we secure?”

It is:

“If one part of our digital ecosystem is compromised, how far can the attacker go?”

That is the question organisations need to answer before the next notification appears.

This article is for general information only and does not constitute cybersecurity, legal, financial or professional advice.

Sources

  • Cybernews: ASOS hack investigation and customer-data risks.
  • LinkedIn News: Cybersecurity experts react to the ASOS hack.
  • UK National Cyber Security Centre: Incident affecting ASOS customers.
  • ASOS Customer Care: Unauthorised ASOS Notification.
  • Recorded Future News: ASOS push-notification incident and market reaction.
  • ITPro: Cybersecurity expert reaction to the ASOS incident.