ASOS Hacked Notification: What Is Known and What to Do
ASOS app users received a notification claiming the retailer was hacked. ASOS has confirmed nothing. What is actually known, and what customers should do now.

- Published
- Reading time
- 7 minutes
ASOS customers in the UK, US, Germany and Australia received a push notification through the retailer's own app on Tuesday morning titled "ASOS HACKED", in which the senders claimed to have compromised the company's Snowflake data platform and threatened to leak information unless ASOS engaged with them. The message was addressed to ASOS's data protection officer and IT team and included a link to a Telegram channel. ASOS has not confirmed that any breach occurred, that its Snowflake environment was compromised, or that any customer data was accessed. Customers are advised not to click the link and to wait for official guidance from the company. ASOS shares fell 11% in morning trading.
Do not click the link
Taking the only genuinely urgent thing first.
The notification contains a link to a Telegram channel. Do not open it. Whoever sent that message has demonstrated access to a system capable of reaching ASOS customers directly, and there is no good reason for a customer to follow a link supplied by them.
There is a second, larger risk arriving behind this one. Every publicised breach or suspected breach is followed within hours by phishing campaigns impersonating the company, because scammers know customers are now expecting to hear from ASOS about their account.
So for the next few weeks: treat every ASOS email, text and message with suspicion. Do not click links in them. If you want to check your account, type the address into your browser yourself or open the app directly. Any message asking you to confirm card details, reset a password via a link, or verify your identity urgently should be assumed fraudulent regardless of how convincing it looks.
That advice holds whether or not a breach turns out to have occurred.
What the message said
The notification was headed "ASOS HACKED".
It opened: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance." It went on: "Engage with us, or we will leak it." Below that sat a link to a Telegram chat.
DPO stands for Data Protection Officer, the role legally responsible for data protection within an organisation. Snowflake is a cloud data platform used by a very large number of major companies to store and analyse data.
Reports of the notification came from users in at least four countries the UK, the United States, Germany and Australia.
The genuinely strange part
Ransom demands are normally made privately. Attackers contact a company directly, negotiations happen out of sight, and the organisation retains the option of resolving matters without public scrutiny.
That is not what happened here. A message explicitly addressed to ASOS's internal data protection and IT staff was delivered instead through the company's own customer notification system the channel ASOS uses to tell shoppers about sales, new stock and delivery updates.
Either the attackers could not reach ASOS's internal teams any other way, or they chose maximum public pressure deliberately. Both readings point the same direction: this was designed to be seen.
It also has a specific legal consequence. Under UK data protection rules, organisations generally have 72 hours to notify the Information Commissioner's Office after becoming aware of a personal data breach that poses a risk to people's rights and freedoms, and must inform those affected without undue delay where the risk is high. By making the claim public, the attackers have placed ASOS in a position where any confirmed breach must be reported, removing the option of quiet resolution.
BREAKING: ASOS customers have received a push notification saying the e-commerce giant had been 'hacked' Sky's Phoebe Southworth has the details. https://t.co/7BFsCqBOSG https://t.co/4HuvhGLNqk
— Sky News (@SkyNews) October 6, 2026
What is actually established, and what is not
This distinction is the whole story, and most coverage is blurring it.
Established: a message was sent through ASOS's app notification system to customers in multiple countries, claiming a compromise.
Not established: whether ASOS's Snowflake environment was compromised, whether any customer data was accessed, how much, or whose.
Security researcher Graham Moore put the logic precisely: "The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS's connected systems, but it doesn't prove their full claims about the extent of the data breach."
That is the honest position. Being able to send a notification demonstrates access to something. It does not demonstrate access to everything, and attackers claiming a full compromise have an obvious incentive to overstate.
ASOS has acknowledged reports of the incident but has not confirmed the Snowflake claim or that customer data was stolen. At the time of writing, the ASOS website appeared to be functioning normally.
What ASOS holds about you
This is the reason the story has landed as hard as it has.
ASOS operates Simon AI, a system that builds a detailed profile of each customer by combining behavioural, transactional and demographic data. In practice, a fashion retailer's customer record can include what you buy, how often, at what price points, your clothing sizes and in some cases body measurements, alongside name, email, delivery and billing addresses, phone number and date of birth.
That is a more intimate dataset than most people picture when they think about a shopping account, and it is precisely the sort of information that makes convincing impersonation possible. Someone who can tell you your dress size, your last order and your address sounds considerably more like ASOS than a generic phishing email does.
None of which establishes that any of it has been accessed. It explains why the possibility is being taken seriously.
What to do now
Do not click the link in the notification. Already said, worth repeating.
Change your ASOS password, and do it through the app or by typing the website address yourself rather than through any link you have been sent. If you have used that password anywhere else, change it there too credential reuse is how a single breach becomes several.
Turn on two-factor authentication if ASOS offers it on your account.
Check your saved payment methods. Many customers have already removed stored cards as a precaution. There is no confirmed evidence that payment data has been accessed, but removing a saved card costs you nothing but a minute at your next checkout.
Watch your bank statements for the next few months, including small unfamiliar transactions, which are often used to test whether a card is live.
Be sceptical of every ASOS communication for the foreseeable future, including ones that look entirely legitimate.
Wait for ASOS's own statement before acting on anything else. If a breach is confirmed, the company is legally required to tell affected customers directly where the risk is high.
There was a separate ASOS breach in August
Worth knowing, with the caveat that no connection between the two has been established.
In August, ASOS US Sales LLC issued a breach notification covering a separate incident. Unusual activity had been detected in certain ASOS accounts on 28 July 2026, in what was described as credential-based account takeovers — attackers using login details exposed in unrelated breaches, phishing or malware to access accounts.
ASOS said the accessed account information may have included names, email addresses, delivery and billing addresses, telephone numbers, dates of birth and details of associated social media accounts. Its security operations team blocked access to affected accounts and enforced mandatory password resets.
That incident was reported as affecting more than 100,000 people. The public notification was dated 21 August, over three weeks after detection.
Two incidents in roughly two months is the kind of pattern that will attract regulatory attention if the current claim is substantiated.
The market reaction
ASOS shares dropped 11% in morning trading following the notification.
That is a substantial move on an unverified claim, and it is a reasonable measure of how seriously investors treat the possibility of a major customer data breach at a retailer whose entire business is online.
What happens next
An ASOS statement. The company has acknowledged reports without confirming anything. Its own account is the next thing to expect and the only one that settles the question.
Any ICO notification. If ASOS concludes a reportable breach occurred, it has 72 hours from becoming aware to notify the Information Commissioner's Office.
Whether the attackers publish anything. A threat to leak is not evidence of having anything to leak. If data appears, the scale becomes clear quickly.
How the notification system was reached. Whether the attackers compromised Snowflake as claimed, or accessed the push notification infrastructure by some other route, is the technical question that determines how serious this is.
Questions readers ask
Has ASOS been hacked?
It has not been confirmed. ASOS customers received a push notification through the retailer's own app on Tuesday claiming attackers had compromised its Snowflake data platform, but ASOS has acknowledged reports of the incident without confirming that a breach occurred, that its Snowflake environment was compromised, or that any customer data was accessed.
What did the ASOS notification say?
It was titled "ASOS HACKED" and read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance", followed by "Engage with us, or we will leak it". It included a link to a Telegram chat. DPO refers to the Data Protection Officer and Snowflake is a cloud data platform used by many large companies.
Should I click the link in the notification?
No. Customers are being advised not to click links contained in the notification and to wait for official guidance from ASOS.
Has any customer data been stolen?
This is not known. Security researcher Graham Moore noted that the attackers' ability to send a push notification suggests they gained access to at least some of ASOS's connected systems, but does not prove their wider claims about the extent of any breach. ASOS has not confirmed that any customer data was accessed.
What should ASOS customers do?
Do not click the link in the notification. Change your ASOS password through the app or by typing the website address directly rather than through any link, and change it anywhere else you have used the same password. Enable two-factor authentication if available. Consider removing saved payment methods as a precaution, monitor bank statements for unfamiliar transactions, and treat all ASOS emails and messages with suspicion, since publicised breaches are routinely followed by phishing campaigns impersonating the company.
Is my payment information at risk?
There is no confirmed evidence that payment data has been accessed. Many customers have removed saved cards as a precaution, which costs nothing beyond re-entering details at the next checkout. Monitoring bank statements for small unfamiliar transactions is sensible, as these are often used to test whether a card is active.


