ASOS 'hacked' alert live — all the latest from security experts as customers receive threatening message
The latest on a scary morning for ASOS customers
The online shopping giant ASOS has seemingly been hacked today, with customers receiving a threatening notification from the mobile app.
The message (titled "ASOS HACKED") was sent on Tuesday morning via a push alert in the ASOS app and security experts have told us that "the potential scope is significant". We've contacted ASOS, but so far it hasn't publicly commented on the issue.
You can follow all the latest developments live with us, including the latest advice on what you should do if you're one of the site's 17 million global customers...
Potential ASOS hack — the latest news
- ASOS customers reported receiving a threatening alert on Tuesday morning
- The alert was titled 'ASOS Hacked' and linked out to a Telegram chat
- ASOS hasn't yet officially commented on the security issue
The attackers didn't just steal from ASOS. They used ASOS's own voice to tell its customers about it. That's not just a data breach. That's a complete loss of operational control, and the reputational damage from that alone is significant.
Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress
Now is not the time for Asos customers to panic because so little is known about the severity of the reported data breach. Its best to never open notifications from retailers in texts or emails and never click on any of the links received. Customers should go directly to the Asos website for more information about the breach. For all organisations, this breach is another reminder about the importance of adopting an assume breach mindset because incidents will inevitably occur and no company is immune to being attacked. Overall, companies that prepare in advance of incidents improve their chances of minimising disruptions to their business. In addition, it doesn’t pay to pay ransoms because not only does it further fuel the ransomware economy, but it doesn’t guarantee the threat group will hand over decryption keys upon payment. Maintaining strong backups and scheduling tabletop exercises regularly is extremely important. Organisations should also have a crisis response plan available to activate during cyber related incidents that ties back to regularly scheduling table top exercises, so stakeholders are familiar with the initial steps and actions to deploy when an incident is discovered
Jeff Wichman, Senior Director of Breach Preparedness and Response at Semperis
Snowflake is a data analysis and AI platform used by several organizations. In 2024, ShinyHunters hacked Snowflake instances of over 160 organizations and stole sensitive data that was used for extortion. They used credentials obtained from infostealers for initial access. This recent hack may be similar, although it is not confirmed what the initial access was. Snowflake has published more than 20 vulnerabilities on their products in 2026, including three considered high criticality in September, but none of those is known to be exploited by threat actors. The threat actors provided a link to a Telegram channel created today that already has 150+ subscribers. That channel then links to a group chat with more than 260 participants. "Xuanye" is not a known threat actor, but the name is of Chinese origin, which could indicate a Chinese-speaking threat actor or simply a false flag
Daniel dos Santos, VP of research at Forescout
Snowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the ASOS mobile app also. This is clear public extortion. Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.
Dray Agha, senior manager of security operations at Huntress
It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access
Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes
What should you do?
Did you get the ASOS 'hacked' notification? If so, there are a few important things that you shouldn't do, including clicking the Telegram link in the message. You should also:
- Avoid clicking links in any suspicious emails
- Do not click links in any suspicious texts or messages
Other cybercriminals could try to exploit the hysteria caused by the ASOS notification, so you should be particularly wary of emails telling you your account has been compromised, or asking you to reset your password.
It's also wise to be careful about shopping on ASOS until the company comments publicly on the issue, which hasn't happened yet.
What did the alert say?
Anyone else get the ASOS hacked notification? Any ideas? https://t.co/WZkWta5dekOctober 6, 2026
ASOS customers first reported receiving the push alert above on Tuesday morning at around 4.55am ET / 9.55am BST.
This coincided with a spike in reports on Downdetector. The message is addressed to ASOS' data protection officer (DPO) and IT team, but was sent to customers.
The 'Snowflake' the message refers to is a Software-as-a-Service (SaaS) that organizations use as a dedicated cloud environment to store, process, and analyze data. This is what has concerned security experts, although it's a little early to say whether customer data has been compromised.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.