Skip to content
Asos hacked latest: Customers sent bizarre, threatening notification by shopping app

Asos hacked latest: Customers sent bizarre, threatening notification by shopping app

Independent • October 6, 2026

Want to bookmark your favourite articles and stories to read or reference later? Start your Independent Membership today.

Already a member? Log in

The Independent Security channel is brought to you by Bitdefender

Asos appears to have been hacked, with customers sent a bizarre, threatening notification.

Users of the app received a message on Tuesday morning indicating that the company’s systems had been compromised.

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message, apparently written by the cyber attackers, reads. “Engage with us, or we will leak it,” it continues, before linking out to a Telegram chat.

DPO refers to the data protection officer, the appointed person in a company who takes responsibility for safeguarding customers’ information. Snowflake is an online data platform used by a wide array of companies.

Asos did not immediately respond to a request for . It is also yet to post the notification or possible cyber attack on its social media accounts.

It is not clear how many customers the notification was sent to. But it appears to have been delivered to at least a large number of the app’s customers.

Asos says that it has 17 million customers each year, in more than 150 countries. That was down slightly on last year, when 19.7 million people shopped on the site.

It reported revenues of £2.5 billion in 2025, down from £2.9 billion the year before. That led to an operating loss of £212 million last year.

Notification makes hack particularly concerning, expert warns

The specific nature of the notification “makes the threat considerably more convincing and potentially much more damaging”, said Marijus Briedis, chief technology officer at NordVPN. And not only because it is a concerning message in itself, but also because it could lead to yet more dangers for customers.

“This is an unusually brazen and threatening message,” he said. “The attackers aren't simply claiming to have breached ASOS - they're publicly telling the company to engage with them or they will leak what they say they have obtained.

“What makes it even more concerning is how that threat appears to have been delivered. A message apparently written for ASOS's data protection and IT teams has instead been pushed directly to customers through the company's own app notification system. That suggests someone has gained unauthorised access to at least part of ASOS's systems, although we don't yet know how extensive that access is.

“The attackers claim they have ‘fully compromised’ ASOS's Snowflake instance. Snowflake is a cloud data platform businesses use to store and analyse large quantities of information. If that claim proves genuine, the critical question will be what information was held there and whether any of it was accessed or downloaded. At this stage, however, customers shouldn't assume their personal or payment information has been stolen - that hasn't been established.

“What customers should be particularly alert to now is what happens . High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.

“Don't click links in unexpected messages, even if they look convincing. Go directly to the ASOS app or website instead. Customers should also make sure their ASOS password is unique and, if they've used the same password elsewhere, change it on those accounts too.

“Until ASOS completes its investigation, we won't know exactly what has been accessed or how the attackers got in. But this incident shows how powerful access to a trusted communications channel can be. When an attacker can potentially speak to customers through a company's own systems, it makes the threat considerably more convincing and potentially much more damaging.”

What could happen to Asos?

If the worst fears the hack are true, then Asos could face substantial punishment, says Lewis McKeown, a commercial lawyer at law firm Square One.

“Should the hackers be successful in leaking the personal data of ASOS customers then the business could face devastating financial and reputational consequences,” he said.

“UK GDPR, supplemented by the Data Protection Act 2018, places obligations on businesses to maintain appropriate security measures and respond appropriately to personal data breaches.

“Where a breach is likely to pose a risk to individuals’ rights and freedoms, companies generally have to notify the Information Commissioner’s Office (ICO) without undue delay and, where possible, within 72 hours of becoming aware of it, with higher-risk breaches potentially requiring direct notification to affected customers, which we’ve already seen this morning courtesy of the alert sent out from the Asos app.

“The ICO could then investigate whether the company had appropriate technical and organisational measures in place and, depending on the circumstances, enforcement action and a significant fine may follow.

“Beyond regulatory fines, the business could also be faced with compensation claims from customers, the cost of investigating and remediating the breach and eroding customer and investor trust, as well as a damaged commercial reputation.”

Expert advises customers to check their accounts and be wary of scams

Customers should make sure they are protecting their accounts and beware of anything that might be a scam, warns Junade Ali, cybersecurity Expert and fellow at The Institution of Engineering and Technology. (It’s important to note that we still know very few details the attack, including whether personal data has actually been stolen – but this is good advice whatever has happened.)

“This is yet another example of criminal hackers using data for extortion purposes,” he said. “A threat actor has essentially pushed a notification on the ASOS app threatening to leak a corporate database if ransom demands are not met.

“Typically ransomware actors will also seek to encrypt data unless a ransom is paid, but there is no evidence of that here and cybersecurity best practice to have backups to minimise the risk of this happening. Here the threat actor has chosen to make the compromise visible, which is not uncommon for extortion purposes.

“Users should take steps to ensure they are using randomly-generated, long, unique passwords for different accounts, enable Two-Factor Authentication where possible, and back up important data. Be wary of scammers who may attempt to use any personal data for scams.”

Cyber attack does not appear to have affected website or app

Asos’s website and app appear to be functioning as usual, despite the alarming message and apparent hack. Visitors still see the usual website (including no information the attack itself).

price continues to plunge

Asos’s shares have now fallen 12.5 per cent since 10am, around the time the notification was sent. That means it has lost £70 million in value.

This year had been something of a turnaround for ASOS, which has been troubled in recent years . It is still up around 56 per cent from where it started the year, even despite the plunge in the wake of the hack.

But the troubles nonetheless continue affect the company deeply, even before today. It has posted losses of hundreds of millions of pounds in recent years, and its shares have lost 84 per cent of their value over the last five years.

Hack is 'one of the most visible' in history, says expert as he warns users not to click on notification

Don’t click on that notification, or follow the Telegram link that’s in it. That’s the advice from one cyber security expert.

“This has got to be one of the most visible hacks in history. The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS’s connected systems, but it doesn’t prove their full claims the extent of the data breach. The threat actors say they have compromised the Snowflake cloud data platform, which would put a lot of customer data at risk,” said Jake Moore, global cyber security adviser at ESET.

“By broadcasting their breach directly to ASOS app users, the threat actors are likely trying to apply pressure to ASOS, showing how extensive their access is so they can leverage some sort of ransom. ASOS app users should not click on the notification and avoid the temptation to engage in the Telegram account if it was shown for them.”

'ASOS hacked' notification in full

Here’s what the message sent to customers reads.

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message, apparently written by the cyber attackers, reads. “Engage with us, or we will leak it,” it continues, before linking out to a Telegram chat.

DPO refers to the data protection officer, the appointed person in a company who takes responsibility for safeguarding customers’ information. Snowflake is an online data platform used by a wide array of companies.

The notification claims that hackers have “fully compromised the Snowflake instance”. (We have no idea at the moment whether that is true: while the ability to send the notification itself suggests that cyber attackers do have access to some Asos systems, we don’t know which or how extensive their break-in is.) But what is Snowflake?

It is, in short, a data platform. It offers a cloud platform that allows its customers to store and analyse their data. As with many companies in recent times, Snowflake’s marketing particularly focuses on its AI tools, but it also offers more traditional data storage and analysis too.

It says it has more than 12,000 customers, which includes brands including the New York Stock Exchange and OpenAI. Snowflake doesn’t mention Asos on its website, but a listing suggests that it is a user of “Simon AI”, a separate product works with Snowflake and uses artificial intelligence to help with marketing.

“Instance” is a computing term for a specific and particular piece of software. In this case (and if the claims are true), it would probably refer to Asos’s data on Snowflake’s servers.

Asos price plunges after notification

Asos’s price has dropped around 5 per cent in the last half hour, since the notification was sent, and it continues to fall.

What does Asos have to do?

UK law requires British companies such as Asos to report any data breaches to officials within three days. Companies must also quickly notify any affected people, in the case of “high risk” hacks.

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Extracted Entities

Attack Types (1)

Companies (2)

Domains (2)

Platforms (2)