Skip to content
Asos Cyber Breach Linked to Employee Credential Theft

Asos Cyber Breach Linked to Employee Credential Theft

First seen 9 Oct 2026, 12:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 13:34 UTC
  • •Asos was hacked via employee credential theft, not a Snowflake vulnerability.
  • •No sensitive payment information was compromised in the breach.
  • •Asos and Snowflake are actively communicating with customers regarding safety measures.

Asos reported a cybersecurity breach where an unauthorized party accessed an employee account by impersonating a trusted source to obtain login credentials. The attacker claimed to have compromised the Snowflake instance used by Asos, but Snowflake confirmed that the breach was not due to any vulnerability in its platform. Asos stated that no payment card information or account passwords were accessed, and the website and app remain safe to use. Customers were alerted about the breach via phone notifications, and Asos has advised them to be cautious of unsolicited communications. The incident is under investigation, and no remediation is required for Snowflake customers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
Asos notifies customers of breach
Customers received alerts about unauthorized access and potential data exposure.
Uk.Finance.Yahoo
2026-10-06
Asos investigation reveals attack method
Asos confirmed that an unauthorized party accessed an employee account through impersonation.
Uk.Finance.Yahoo
2026-10-07
Snowflake issues statement
Snowflake confirmed that the breach was not due to any flaw in its platform and reassured customers.
Theguardian

More articles in this cluster (2)

Following this threat?

Track ASOS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What data was compromised?
Asos stated that no payment card information or account passwords were accessed, only some personal data.
How did the breach occur?
The breach occurred through an employee account being accessed by an unauthorized party impersonating a trusted source.
What should Asos customers do?
Asos advises customers to remain cautious of unsolicited messages and calls claiming to be from the company.