ASOS Confirms Unauthorised Hack Notification; Customer Data May Be Exposed

 

On 6 October 2026, thousands of ASOS customers across multiple countries received a shocking push notification via the official ASOS app, claiming that hackers had breached the retailer’s systems. The message, which appeared around 10:00 BST, was addressed to ASOS’s data protection officer and IT team and warned that attackers had “fully compromised the Snowflake instance” and would leak data unless the company engaged with them. ASOS swiftly described the alert as an “unauthorised customer notification” and launched an investigation into what appears to be a cyber-extortion attempt routed through a third-party communications platform. 
The notification was headlined “ASOS HACKED” and read: “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” followed by a link to an external Telegram channel signed by a user called “xuanyewengateway”. Many users reported feeling scared and confused, with some saying they no longer trusted the ASOS app after seeing the message arrive through what should be a secure, brand-controlled channel. Security experts described the incident as a brazen attempt to pressure ASOS publicly by hijacking its own customer-notification system, raising concerns about how attackers gained access to such a sensitive communications tool. 
In response, ASOS said it took immediate action to restrict access to the notification platforms and is working with internal and external cybersecurity specialists, as well as relevant authorities. The company confirmed that basic personal information, including names and contact details, may have been accessed during the incident, but it does not believe payment-card information or account passwords were impacted. ASOS stressed that its website and app remain fully operational and urged customers to disregard the unauthorised alert and not click any links contained within it, warning that doing so could expose them to further risks.
ASOS is not currently asking customers to change their passwords or take other specific actions, but it advises anyone who received the notification to ignore it and avoid engaging with the third-party link. The UK’s National Cyber Security Centre has gone further, suggesting that all ASOS customers should consider themselves potentially affected, even if they did not see the alert, and should only access ASOS via its official website or app. Users are also warned to be alert for follow-up scams, such as fake refund or support messages exploiting concern over the incident, and to treat any unexpected communication about the breach with caution. 
ASOS says its investigation into the unauthorised activity involving third-party communication platforms is ongoing, and it will provide updates if the situation changes. While the attackers claimed a Snowflake data-platform breach, Snowflake itself has stated it has found no compromise of its platform at this time. For now, ASOS maintains that push notifications are safe, operations are unaffected, and customers can continue to shop with confidence while the company works with cybersecurity advisers and law enforcement to understand exactly how the unauthorised message was sent and to prevent similar incidents in the future.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: