Skip to content
Why was Asos hacked and who did it?

Why was Asos hacked and who did it?

Independent • October 7, 2026

Want to bookmark your favourite articles and stories to read or reference later? Start your Independent Membership today.

Already a member? Log in

The Independent Security channel is brought to you by Bitdefender

Asos customers have received an alarming notification on their phones – and very little information what happened and what they should do .

On Tuesday, the online clothing retailer’s app sent a threatening notification to a huge number of users. It appeared to be the result of a cyber attack that allowed hackers access to at least some of Asos’s systems.

But it still remains unclear precisely what happened. Despite that, however, there are plenty of important steps that customers can take.

Here’s everything we know the hack , and what worried customers should do .

Shortly before 10am on Tuesday, Asos customers received a threatening notification through the app . “ASOS HACKED,” it began.

“Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

The hackers linked out to a Telegram account, which identified them as “Xuanye Group”, a name that has not been used before. In that group, the hackers made no specific demand and perhaps surprisingly seemed to advise users to remain calm, telling them that the site would keep working and claiming that they had not accessed financial data.

After that notification, however, came a lot of silence. Even now, long after the notification was sent, much remains unclear what actually happened.

The short answer is yes. Asos has admitted that the notification was “unauthorised”, and warned that “personal information including name and details may have been accessed”.

The ideal summer spot? Away from scams.

Get All-in-One Protection for Your Digital Life

The ideal summer spot? Away from scams.

Get All-in-One Protection for Your Digital Life

But it remains unclear how it was hacked and what exactly was hacked. Asos only made specific reference to the notification, and stressed that its “website and app are operating as normal, with no current disruption to any aspects of our operations”, which may suggest that the cyber attack only affected the tool it uses to send out notifications on its app.

But we still don’t know – and it is of course possible that Asos doesn’t know for sure. The company says it is investigating, and given it is both a public company and is covered by the fairly strict rules that govern how UK companies use customer data, we should hear the results of that investigation soon.

After five hours of silence, the company finally released a full statement on Tuesday afternoon.

“Asos can confirm that, at around 10am today, an unauthorised customer notification was sent to Asos customers,” it said.

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.

“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.

“Basic personal information including name and details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.

“Our website and app are operating as normal, with no current disruption to any aspects of our operations.

“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.

“The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.”

What should customers do?

Given the lack of information what happened, it is unclear exactly how worried Asos customers should be. But experts warned people not to panic.

“Getting a message like that from an app you trust is genuinely unsettling,” said Pete Membrey, chief research officer at ExpressVPN. “Most people think of a hack as something that happens out of sight, so seeing a threat land on your own phone makes it feel much more personal.

“t's completely understandable that people are worried, but the most important thing right now is not to panic. At times like this, panic can make matters much worse.

"The truth is we don't know much yet, and 'don't know' means don't know. A knee-jerk reaction could be exactly the wrong thing to do.”

Instead, experts advised customers to take the usual precautions. That includes not clicking on the link in the notification, changing passwords on Asos and not re-using them, turn on two-step verification on apps that use it and staying alert to any potentially suspect activity on other apps or in your bank.

Experts also advised that the effects of any hack could be wide-ranging – far beyond Asos itself. And so it is important to take that same vigilance and apply it across the internet, they said.

“What customers should be particularly alert to now is what happens . High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund,” said Marijus Briedis, chief technology officer at NordVPN.

“Don't click links in unexpected messages, even if they look convincing. Go directly to the ASOS app or website instead. Customers should also make sure their ASOS password is unique and, if they've used the same password elsewhere, change it on those accounts too.”

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Extracted Entities

APT Groups (1)

Attack Types (2)

Companies (2)