Skip to content
ASOS confirms cyber attack, warns of 'personal information' access

ASOS confirms cyber attack, warns of 'personal information' access

Retailsector • October 7, 2026

ASOS has confirmed that customers’ “basic personal information” may have been accessed following a cyber security incident earlier today. It comes as a notification was sent to app users earlier this morning stating: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

The retailer said it is investigating the unauthorised messaging and took “immediate action” to restrict access to its notification platforms. Internal and external specialists, along with relevant authorities, have also been called in to assess the breach.

In a statement released today, ASOS said: “ASOS can confirm that, at around 10am today, an unauthorised customer notification was sent to ASOS customers. We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

“Basic personal information including name and details may have been accessed. We do not believe that payment-card information or account passwords were impacted.”

It added: “Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.

“The company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.”

Extracted Entities

Attack Types (1)

Companies (2)