ASOS Hacked? What the Alert Means and What to Do

ASOS hacked is the headline, but here’s the accurate version: ASOS is investigating a claimed cyberattack, and it hasn’t confirmed that any customer data was stolen. If you got the alert, don’t tap the link. Watch for emails, texts and calls that claim to be from ASOS over the next few weeks.

Was ASOS hacked? What we know so far

On Tuesday, October 6, 2026, LBC reported that thousands of users got a push notification shortly before 10am. It was addressed to ASOS’s data protection officer and IT team, claimed the Snowflake instance was “fully compromised,” and told the company to engage or face a leak. A Telegram link was attached.

Cybernews says the notification was titled “ASOS HACKED.” City AM reports that people in the UK, US, Germany and Australia saw it.

ASOS’s response so far is thin. Reuters, via MarketScreener, says a spokesperson was aware of the reports but didn’t confirm or comment further. The website and app stayed up. Nobody has publicly said what data, if any, was taken.

Why does the push notification matter?

ASOS Hacked? What the Alert Means and What to Do

Anyone can write a scary message. Getting it into an official app notification is harder. ESET’s Jake Moore told reporters the incident could be one of the “most visible hacks in history”. He also said that being able to send the notification suggests the attackers reached at least part of ASOS’s systems, though the full claim is unverified.

That’s an inference, and it’s unconfirmed. A push-messaging account or a third-party tool could have been abused without anyone touching the customer database. The notification proves some kind of access. It doesn’t prove the stolen-data claim.

The City AM report says it’s still unclear how the attackers sent the message, whether Snowflake was compromised as claimed, or how many customers are affected.

What is Snowflake, and should it worry you?

Snowflake is a cloud data platform that many large companies use to store and analyze data. The ASOS alert named it, so any stolen data would plausibly be analytics or customer records. That’s speculation until ASOS says otherwise.

Must check: 10 Cybersecurity Tips for Everyday Users(2026)

There’s history here. In 2024, a hacking campaign hit as many as 165 Snowflake customers. Bloomberg reported that attackers used stolen credentials on accounts without multifactor authentication, rather than breaking Snowflake itself. That doesn’t tell us how ASOS’s situation came about. It does show that “Snowflake breach” usually means weak access controls at the customer, not a flaw in the platform.

How much has this hurt ASOS so far?

The market reacted fast. Reuters reported shares dropped more than 11% on Tuesday. Investing.com says they fell as much as 13.2% before paring losses to around 9%. The exact figure depends on when you check.

The exposure is large. ASOS has around 17 million active customers across more than 150 countries, according to City AM’s 2026 report.

This also isn’t ASOS’s first problem this year. In August 2026, ASOS US Sales LLC notified US customers that attackers had used credentials obtained outside the company to access accounts. A law firm’s investigation put the number at roughly 138,828 people. There’s no confirmed link to Tuesday’s alert.

Is this part of a wider run of UK retail attacks?

Yes, the timing fits a pattern. The April 2025 attacks on Marks & Spencer and the Co-op were assessed by the Cyber Monitoring Centre as a combined event costing £270 million to £440 million (2025).

A 2026 Marsh survey of 350 UK retail executives found that 95% say their business has significant areas of cyber exposure. Retailers hold a lot of personal data and have to keep trading, which makes them attractive targets.

What should ASOS customers do right now?

Most of the risk is in what happens next. GB News quoted a security expert who expects criminals to exploit the confusion. That means fake password-reset requests, payment confirmations, order updates and refund offers, sent by email, text or social media.

  • Don’t tap the Telegram link or try to contact the sender. Experts quoted by Eastern Eye say the same.
  • Don’t use links in messages. If you want to check your account, open the app or type the address yourself.
  • Change your ASOS password if you’ve reused it anywhere, and fix those other accounts too. Start with your email.
  • Turn on two-factor authentication where it’s offered, and use a password manager so every site gets a unique password.
  • Check your card statements over the coming weeks. Report anything odd to your bank.
  • Report scams. In the UK, forward suspicious emails to report@phishing.gov.uk and texts to 7726. In the US, report to the FTC at ReportFraud.ftc.gov.

ASOS itself publishes cyber security guidance. It says to avoid clicking links or opening attachments in emails you doubt.

If you’re a US customer who got the August account-access notice, the same rules apply, and a credit freeze is worth considering if you suspect identity misuse. eSecurity Planet suggests reviewing your credit reports and considering a fraud alert. [LINK: how to set up a password manager]

What happens next?

UK law puts pressure on ASOS. LBC notes that British companies must report data breaches to officials within three days and notify affected people quickly when the risk is high. If a breach is confirmed, expect a regulator filing and an email to customers. [LINK: what to do after a data breach notice]

Until then, treat any message about this as suspect, including ones that look like ASOS updates. If ASOS contacts you, it should be through the app or an email you can verify from the account itself.

Must check: 283 Dangerous Android Apps: Uninstall these apps immediately

FAQ

Has ASOS confirmed it was hacked?

No. A spokesperson told Reuters the company was aware of the reports but didn’t confirm or comment further. The site and app kept working, and ASOS hasn’t said what data, if any, was accessed.

Is my ASOS account safe?

We don’t know yet. Nothing public confirms customer accounts were exposed in this incident. Use a unique password and two-factor authentication, and avoid any link in a message about this. That covers you either way.

What does Snowflake have to do with ASOS?

The threatening notification claimed the attackers had “fully compromised” ASOS’s Snowflake instance. Snowflake is a cloud data platform used by many companies. ASOS hasn’t confirmed the claim, so it’s unclear what data, if any, was involved.

Should I delete the ASOS app?

You don’t have to. Deleting the app doesn’t remove your data from ASOS’s systems, and the notification itself isn’t dangerous unless you tap the link. If you’d feel safer, log out, and update the app when ASOS releases fixes.

How can I tell if an ASOS email is fake?

Be suspicious of anything about this alert, such as a refund, a forced reset or an unexpected order. Don’t click anything. Go to the app or type asos.com yourself to check your account.

You May Also Like

77dbfd2880cf66e2c8fa2dd5ad9767fcb7587999aceea8a80a965cbf5d13fc19

About the Author: Sourabh Kumar

Sourabh Kumar Singh is an Electronics and Communication Engineer based in Jaipur, India, with 10+ years of experience in SEO, digital marketing, content creation. He specializes in translating complex topics - ranging from technology and automobiles to sustainability and education - into engaging blogs, scripts, reviews, and whitepapers. Currently perfecting his dream office workspace, Sourabh spends his weekends off-roading on his motorcycle, practicing quilling art, and capturing stories through photography.

Leave a Reply

Your email address will not be published. Required fields are marked *

Translate »