Skip to content
The ASOS Data Breach Exposed Millions of Customers' Details

The ASOS Data Breach Exposed Millions of Customers' Details

Cybermagazine • October 8, 2026

The ASOS cyber incident has had a major escalation, with the fashion giant acknowledging that hackers now possess details belonging to millions of customers.

Users of the ASOS app had received a push notification on 6 October 2026, with the title “ASOS HACKED”, noting that hackers had “fully compromised” the company’s Snowflake instance.

The retailer has since confirmed the incident and commented in a statement that “basic personal information including name and details may have been accessed”.

The situation has since escalated, after the hackers contacted BBC News on 7 October 2026 to a sample set of stolen data, which the outlet says, “showed the true extent of the hack ”.

BBC had refrained from publishing to allow the retailer to inform the customers, which it did via email.

According to the report, cybercriminals behind the hack are now in possession of names, addresses, phone numbers, emails, data and customer numbers of ASOS users.

The company confirmed in the email that no bank details or passwords were accessed.

How did hackers target ASOS data?

Though ASOS is still investigating the incident, it told customers that cybercriminals had gained access to an employee account through social engineering.

The company explained that hackers did this by “impersonating a trusted to obtain login credentials”.

After logging in, they were able to simply download the customer data.

Every update is an opportunity to rebuild credibility or undermine it further Hayley Goff, CEO of Whiteoaks International

Every update is an opportunity to rebuild credibility or undermine it further

BBC attributes the hack to a group called Xuanyewen, who say it used a platform built on Snowflake called Simon AI to gain access.

Snowflake previously noted that it had not been breached and the BBC has since contacted Simon AI for , the response was not published at the time of writing.

What should ASOS customers and the company do now?

BBC notes that the fashion said it will “ customers directly where we believe additional information, support or action may be required”.

“Please remain cautious of unexpected messages or calls claiming to be from ASOS,” the company warns customers.

“We will never ask you to passwords, security codes or payment details through an unsolicited message or call.”

“The latest revelations create a second challenge for ASOS in maintaining customers’ confidence in what it tells them, as well as its ability to protect their information,” notes crisis communications specialist Hayley Goff, who is the CEO of Whiteoaks International .

“With fuller disclosure following the BBC ’s intervention, there is a risk customers feel the company is responding to scrutiny rather than keeping them informed.

“Investigations take time, but reassurance must keep pace with the evidence.

“Businesses need to distinguish clearly between what they have confirmed and what they are still investigating. When the picture changes, they must explain why.

“For ASOS, the priority now is to make clear what the findings mean for customers and how it is addressing the risks.

“Every update is an opportunity to rebuild credibility or undermine it further.”

“The most important step is to treat any unexpected communication the breach with suspicion, however convincing it may appear,” notes Dr Darren Williams, Founder and CEO BlackFog .

“Legitimate companies won’t ask you to disclose passwords, card details or one-time passcodes through unsolicited emails, texts or phone calls.

“Any such request should be treated as a red flag, even if the sender already knows personal details such as your name, address or date of birth.

“Customer awareness and strong access controls are essential, but they are not enough on their own.

“Organisations must also have technology in place that prevents sensitive data from leaving their environment, even when attackers have successfully gained access to their networks.”

ASOS users received an app push notification titled "ASOS HACKED" on 6 October 2026, and hackers shared a sample of stolen data with the BBC on 7 October 2026

The BBC says the stolen ASOS data includes names, addresses, phone numbers, emails, data and customer numbers

ASOS says no bank details or passwords were accessed

ASOS says hackers accessed an employee account through social engineering, impersonating a trusted to obtain login credentials

The BBC attributes the attack to a group called Xuanyewen, which says it used Simon AI, a platform built on Snowflake

ASOS says it will never ask customers for passwords, security codes or payment details through an unsolicited message or call

Whiteoaks International

Whiteoaks International

Whiteoaks International

Whiteoaks International

CrowdStrike: How a Cyber Attacker hit South Korean Banks Hacking & Malware

Yubico and Okta: Passwords Refuse to Die Across Enterprises Cyber Security

Top 10: Machine Learning Threat Detection Companies Cyber Security

TrendAI: Nation-State Actors, AI & Why China Leads the Pack Technology & AI

Extracted Entities

APT Groups (1)

Attack Types (1)

Companies (2)

MITRE ATT&CK (1)

Platforms (1)