ASOS Hacked: What We Know After Customers Receive Threatening App Alert?
Published By
Olivia
Published:
Updated:

ASOS customers have been warned to stay alert for suspicious messages after the online fashion retailer confirmed a cyber incident in which an unauthorised notification was sent through its customer communications systems.
The incident erupted on Tuesday, 6 October, when shoppers began receiving an alarming push notification through the ASOS app carrying the words “ASOS HACKED”.
The message was directed towards the retailer’s data protection and IT teams and claimed that attackers had compromised a Snowflake environment.
It also threatened that information would be leaked unless the company engaged with the people behind the message.
The notification contained a link directing recipients towards Telegram.
ASOS has since confirmed that the notification was unauthorised and said it is investigating activity involving third-party platforms it uses to communicate with customers.
The development quickly attracted attention because the message did not arrive through a random phishing email or text. It appeared through a communications channel customers normally associate directly with ASOS.
That distinction has made the ASOS hacked incident particularly unusual and has raised questions about how much access the attackers actually obtained.
What Has ASOS Confirmed?
ASOS said the unauthorised customer notification was sent at around 10 am on 6 October.
The company immediately restricted access to the affected notification platforms and brought in internal and external specialists while working with relevant authorities.
More importantly for customers, ASOS acknowledged that basic personal information, including names and contact details, may have been accessed.
However, the company said it does not currently believe payment card information or customers’ account passwords were affected.
ASOS’s website and app have also remained operational, with the company saying there was no current disruption to its wider operations.
Its customer guidance tells shoppers to disregard the unauthorised notification and not to click or interact with the external link contained within it.
ASOS is not currently asking customers to change their passwords. It says affected users will be contacted directly if its advice changes.
There remains an important distinction between what ASOS has confirmed and what the alleged attackers have claimed.
The attackers said they had “fully compromised” a Snowflake instance. That wider claim has not been independently established.
Snowflake, the cloud data company referenced in the message, has also reportedly said that it has found no evidence of a compromise of its platform while investigations continue.
Cybersecurity specialists have therefore warned against assuming that every claim made by the group behind the notification is accurate.
Jake Moore, global cybersecurity adviser at ESET, said the ability to send the notification suggests access to at least part of ASOS’s connected infrastructure, but
“it doesn’t prove their full claims about the extent of the data breach.”
That is a significant distinction.
An attacker obtaining access to a customer-notification platform is serious in its own right, but it does not automatically demonstrate access to every database, customer record or payment system used by the company.
The technical investigation will now need to establish precisely which systems were accessed, what credentials or integrations were involved and whether information was extracted rather than simply viewed.
Why the ASOS Hack Is Unusual?
The most striking element is the way the alleged attackers communicated publicly.
Cyber extortion groups commonly approach companies privately before threatening to publish stolen material.
Here, customers apparently became part of the pressure campaign after the message was distributed using a channel associated with ASOS itself.
Dray Agha, senior manager of security operations at Huntress, described the method as
“clear public extortion.”
It potentially creates two problems for a business simultaneously.
The first is the underlying security incident and the possibility of personal information being exposed.
The second is reputational damage caused by attackers apparently gaining enough access to communicate directly with customers.
Markets reacted quickly.
ASOS shares dropped sharply during trading on 6 October, falling as much as around 13% during the session before recovering some of those losses.
Reuters reported the shares were down around 10% following ASOS’s disclosure that some customer information could have been accessed.
The company said it has cybersecurity insurance with a major global provider, including business-continuity coverage, but added that it was too early to calculate any potential effect on trading.
For a retailer with 16.5 million active customers across more than 100 markets, even relatively limited exposure of names and contact information can create a substantial secondary risk.
That secondary risk is phishing.
Once an incident involving a major brand becomes public, criminals who had nothing to do with the original attack can exploit the publicity.
They might impersonate ASOS and send emails claiming that an order needs to be confirmed, a password must be reset, a refund is waiting or payment information needs updating.
Marijus Briedis, chief technology officer at NordVPN, warned that
“high-profile cyber incidents create ideal conditions for phishing attacks.”
That means customers should treat unexpected ASOS-related communications with additional caution even if those messages arrive days or weeks after the original incident.
The UK’s National Cyber Security Centre has also issued guidance specifically addressing ASOS customers.
The NCSC says ASOS customers should assume they may be affected, even if they did not personally receive the unauthorised push notification.
It recommends remaining alert for suspicious messages, avoiding unexpected links and reviewing account activity for anything unusual.
Customers receiving an email supposedly from ASOS should therefore avoid relying solely on the branding, sender name or urgency of the message.
Opening the ASOS app or typing the company’s website address directly is safer than following an unexpected link claiming immediate action is necessary.
The company itself has specifically told customers not to interact with the Telegram link contained in the unauthorised notification.
The incident is another reminder that cyberattacks against major British businesses are no longer simply technical problems contained within corporate IT departments.

Recent attacks on UK companies have shown how quickly cybersecurity failures can affect customers, supply chains, operations and investor confidence.
In ASOS’s case, the immediate operational impact appears comparatively limited so far.
Its website and app remain available, shopping has continued, and the retailer says it currently sees no evidence that passwords or payment-card information were compromised.
But the investigation remains active.
As of 7 October 2026, ASOS has confirmed unauthorised activity and possible access to names and contact information, while the much broader claim that attackers completely compromised its Snowflake environment remains unverified.
For customers searching “ASOS hacked”, that is currently the most important distinction: a genuine cyber incident has occurred, but the full scale of the attackers’ access has not yet been established publicly.
Until investigators determine exactly what happened, customers are being advised to ignore the original unauthorised notification, avoid suspicious links and remain particularly cautious of emails, texts or messages attempting to capitalise on the incident.

About the Journalist
Olivia covers London life, culture and lifestyle for Londoner. Her work includes food, shopping, neighbourhood trends, attractions, local experiences and practical guides for residents and visitors. She focuses on engaging stories that reflect everyday life across the capital.


