Skip to content
ASOS 'hacked' LIVE: Customers of online store sent alarming message - 'fully compromised'

ASOS 'hacked' LIVE: Customers of online store sent alarming message - 'fully compromised'

Express • October 6, 2026

Fears ASOS has been hacked have emerged this morning, as some customers received a bizarre notification. ASOS customers received the following message on Tuesday: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." A link was also included in the notification. DPO, or data protection officer, refers to the person appointed by a company to oversee the protection and security of customer information. Snowflake, on the other hand, is a cloud-based data platform used by a wide range of businesses. The chilling message was sent via a push notification, which alerted those who have the app downloaded. Shortly before 3.30pm, ASOS issued a first statement on this incident, saying they were investigating "unauthorised activity involving third-party platforms".

THIS LIVE BLOG IS NOW CLOSED. READ OUR COVERAGE BELOW.

Payment information not affected, claim group 14:04

ASOS message in full 11:29

ASOS app customers receive bizarre message 10:59

ASOS customers received the following message on Tuesday: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."

The people who issued the message did not identify themselves in the notification sent to users. However, they attached a link to a Telegram chat, created today, that appears to identify them as “Xuanye Group”.

Despite the strange notification that sparked fears the platform had been hacked, the ASOS website and app appear to be working as normal.

ASOS has yet to release a statement on the issue.

We are now closing this live blog, thank you for following along.

Payment information not affected, claim group

The push notification sent to ASOS app users, included a link to a Telegram channel called the Xuanye group.

On the Telegram channel, the group posted the following message this afternoon:

"Regarding ASOS, payment information is not affected. That is all for now."

"Regarding ASOS, payment information is not affected. That is all for now."

ASOS yet to release statement

After this morning’s notification, seemingly sent by hackers, ASOS has yet to release a public statement.

Have you been impacted by alleged ASOS hacking?

Have you been impacted by the alleged hacking of ASOS? Did you receive the push notification this morning?

If so, feel free to get in touch: [email protected] or via [email protected]

'Hell of a crazy notification to get on your phone'

Here are some more responses from users sharing their reaction to the notification received earlier.

One user on X wrote: "Hell of a crazy notification to get on your phone.. damn."

"It looks like ASOS is having a bad day today!? Never seen a notification like this before", added another.

Who is behind the message sent to ASOS customers?

The group allegedly behind the message did not identify themselves in the notification sent to users. However, they attached a link to a Telegram chat, created today, that appears to identify them as “Xuanye Group”.

This is not a well-known hacking group and there is no indication they have been involved in any cyber attacks in the past.

Potential hack follows series of cyber incidents against British retailers

The potential hack follows a series of cyber incidents targeting British retailers, including Marks & Spencer, the Co-op and Harrods last year.

M&S revealed in May 2025 that the hack was caused by "human error" and would cost the firm around £300 million.

Chief executive Stuart Machin said the hackers gained access to the company's IT systems through a third party.

He said: "We didn't leave the door open, this wasn't to do with under-investment. Everyone is vulnerable. For us, we were unlucky on this particular day through some human error."

'An unusually brazen and threatening message'

Marijus Briedis, Chief Technology Officer at NordVPN, called the push notification "an unusually brazen and threatening message".

Briedis added: "The attackers aren't simply claiming to have breached ASOS - they're publicly telling the company to engage with them or they will leak what they say they have obtained.

“What makes it even more concerning is how that threat appears to have been delivered. A message apparently written for ASOS's data protection and IT teams has instead been pushed directly to customers through the company's own app notification system. That suggests someone has gained unauthorised access to at least part of ASOS's systems, although we don't yet know how extensive that access is.

“The attackers claim they have ‘fully compromised’ ASOS's Snowflake instance."

Issues shows 'the ability of hackers to directly potential victims'

Here is a by Tatyana Shishkova, Lead Security Researcher at Kaspersky:

" The ability of hackers to directly potential victims through push notifications in the ASOS app highlights how disruptive cyber incidents can be when threat actors gain access to trusted communication channels. Beyond the immediate technical impact, incidents like this can quickly undermine customer trust, particularly when alarming messages appear to come from a legitimate organisation. "While attackers have reportedly claimed to have compromised a Snowflake environment, organisations should avoid drawing conclusions based solely on statements made by cybercriminals. Establishing what systems were accessed, what data may have been exposed, and how attackers gained entry requires a thorough forensic investigation."

" The ability of hackers to directly potential victims through push notifications in the ASOS app highlights how disruptive cyber incidents can be when threat actors gain access to trusted communication channels. Beyond the immediate technical impact, incidents like this can quickly undermine customer trust, particularly when alarming messages appear to come from a legitimate organisation.

"While attackers have reportedly claimed to have compromised a Snowflake environment, organisations should avoid drawing conclusions based solely on statements made by cybercriminals. Establishing what systems were accessed, what data may have been exposed, and how attackers gained entry requires a thorough forensic investigation."

ASOS has millions of UK app users

The British online fashion and cosmetic retailer has a strong app presence in the UK, with 40% of its 23 million active mobile and online users globally based in the UK, according to the 2026 ASOS Revenue and Usage Statistics.

The followingimage shows the message ASOS app customers received.

Here’s what the message sent to customers reads.

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message, apparently written by the cyber attackers, reads. “Engage with us, or we will leak it,” it continues, before linking out to a Telegram chat.

ASOS prices tumble

ASOS's prices are feeling the pain with them dropping around 5% over the past hour and it continues to tumble.

ASOS website and app appear to be unaffected

Despite the strange notification, the ASOS website and app appear to be working as normal.

If the retailer has been hacked, it will be required by UK data laws to report any data breaches to officials within three days.

'ASOS hacked', users flood to X to report issues

ASOS app users have flooded to X to their reaction to the apparent hack online.

One user wrote: "ASOS hacked, never deleted my payment methods so quick looool."

Another customer shared a screenshot of the bizarre message and wrote: "Anyone else get the ASOS hacked notification? Any ideas?"

Hundreds of customers report issues with app

Reports of issues with the app appear to have began at around 9.45am this morning, according to Downdetector , which provides real-time outage monitoring.

Shortly before 10am, the site experienced a spike in reported issues, with nearly 500 users reporting problems.

ASOS users reactions after receiving message

Several ASOS customers have taken to social media after receiving an app notification that sparked fears the site may have been hacked.

Group behind message seemingly inviting ASOS to engage with them

The link included in the worrying message appears to be to the messaging apps telegram, if this is a hack it appears that the alleged hackers are inviting ASOS to engage with them.

ASOS app customers receive bizarre message

ASOS customeres recieved the following message on Tuesday: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."

A link was also included in the notification.

Welcome to our live blog

Good morning, my name is Lauran O'Toole and welcome to our live blog. We'll bring you the latest on claims ASOS may have been hacked.

Extracted Entities

Attack Types (1)

Domains (1)

Platforms (2)