At around 10am on Tuesday 6 October, an unauthorised customer notification was sent to Asos customers, it confirmed in a London Stock Exchange update shortly after 3pm.
Basic personal information including name and details may have been accessed, it said. The company does not believe that payment-card information or account passwords were impacted.
“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms, and are working with our internal and external specialist advisers, as well as all relevant authorities,” it said in the statement.
The Asos website and app are operating as normal, and there appears to be no current disruption to any aspects of operations.
“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate,” it said.
It added: “The company has cyber-security insurance with a large global provider, including business-continuity insurance. It is early to quantify any potential impact on trading.”
The etailer has also added a notification on the homepage of its website warning customers not to engage with the notification.
The notification sent to app customers reads: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
If clicked, it brings the user to a Telegram channel called Xuanye gateway that asks them to join a second broadcast channel, the Xuanye group.
“DPO” stands for data protection officer – the person responsible for overseeing an organisation’s data protection and privacy compliance.
The push notification received by some Asos customers on the morning of Tuesday 6 October
The push notification received by some Asos customers on the morning of Tuesday 6 October
Snowflake is a cloud-based data platform that helps companies store, manage, analyse and large amounts of data.
Following the “hack” notification this morning, shares at Asos plunged 12.55%.
“Should the hackers be successful in leaking the personal data of Asos customers then the business could face devastating financial and reputational consequences,” said Lewis McKeown, lawyer at commercial law firm Square One Law.
UK GDPR, supplemented by the Data Protection Act 2018, places obligations on businesses to maintain appropriate security measures and respond appropriately to personal data breaches.
Where a breach is likely to pose a risk to individuals’ rights and freedoms, companies generally have to notify the Information Commissioner’s Office (ICO) without undue delay and, where possible, within 72 hours of becoming aware of it, with higher-risk breaches potentially requiring direct notification to affected customers, he explained.
The ICO could then investigate whether the company had appropriate technical and organisational measures in place and, depending on the circumstances, enforcement action and a significant fine may follow.
“Beyond regulatory fines, the business could also be faced with compensation claims from customers, the cost of investigating and remediating the breach, and eroding customer and investor trust, as well as a damaged commercial reputation,” said McKeown.
Publicly announcing a hack puts psychological pressure on the decision makers, with attackers expecting businesses to panic and succumb to their demands, said senior information security researcher Aras Nazarovas at Cybernews.
“Publishing the message via notifications to users is a double-edged sword here, as that might have a similar effect as an internal message, but now everyone knows the breach, which greatly reduces the likelihood of the ransomware payment actually being made,” Nazarovas said.
“Typically, ransom payments are negotiated in secret, which allows impacted organisations to avoid public scrutiny over data leaks. Now, for instance, Asos will be forced by UK law to report the data breach to officials within three days.”
Alexander Berrai, deputy CEO at Emerchantpay commented: “Retailers have a critical role to play in protecting their customers from fraud by embedding security into every stage of the customer journey and continually adapting defences to keep pace with emerging tactics. With three-quarters of consumers saying security is their top priority when shopping online, businesses that proactively invest in these measures will be best placed to build customer confidence.
“Staying ahead of the rapidly evolving fraud threat will require ongoing collaboration across the payment and retail ecosystem alongside support from policymakers and regulators.”
In 2025 a wave of cyber-attacks sent shockwaves through UK fashion retail. Marks & Spencer shut down some operations to contain the effects of a targeted infiltration.
High-profile breaches at some of the industry’s biggest retailers, including Marks & Spencer, Harrods, LVMH, Adidas and Victoria’s Secret, and in the wider business world, the Co-op Group and Jaguar Land Rover, among others, exposed vulnerabilities in the safekeeping of customer and staff data, alongside disrupting supply chains and internal systems – highlighting just how vulnerable some fashion retail businesses are to a new era of cyber-crime.
See Legal advice for mitigating cyber-risks
Cyber attacks: Is fashion retail more secure?
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
