ASOS hacked is the headline, but here’s the accurate version: ASOS is investigating a claimed cyberattack, and it hasn’t confirmed that any customer data was stolen. If you got the alert, don’t tap the link. Watch for emails, texts and calls that claim to be from ASOS over the next few weeks.
Was ASOS hacked? What we know so far
On Tuesday, October 6, 2026, LBC reported that thousands of users got a push notification shortly before 10am. It was addressed to ASOS’s data protection officer and IT team, claimed the Snowflake instance was “fully compromised,” and told the company to engage or face a leak. A Telegram link was attached.
Cybernews says the notification was titled “ASOS HACKED.” City AM reports that people in the UK, US, Germany and Australia saw it.
ASOS’s response so far is thin. Reuters, via MarketScreener, says a spokesperson was aware of the reports but didn’t confirm or comment further. The website and app stayed up. Nobody has publicly said what data, if any, was taken.
Why does the push notification matter?

Anyone can write a scary message. Getting it into an official app notification is harder. ESET’s Jake Moore told reporters the incident could be one of the “most visible hacks in history”. He also said that being able to send the notification suggests the attackers reached at least part of ASOS’s systems, though the full claim is unverified.
That’s an inference, and it’s unconfirmed. A push-messaging account or a third-party tool could have been abused without anyone touching the customer database. The notification proves some kind of access. It doesn’t prove the stolen-data claim.
The City AM report says it’s still unclear how the attackers sent the message, whether Snowflake was compromised as claimed, or how many customers are affected.
What is Snowflake, and should it worry you?
Snowflake is a cloud data platform that many large companies use to store and analyze data. The ASOS alert named it, so any stolen data would plausibly be analytics or customer records. That’s speculation until ASOS says otherwise.
Must check: 10 Cybersecurity Tips for Everyday Users(2026)
There’s history here. In 2024, a hacking campaign hit as many as 165 Snowflake customers. Bloomberg reported that attackers used stolen credentials on accounts without multifactor authentication, rather than breaking Snowflake itself. That doesn’t tell us how ASOS’s situation came about. It does show that “Snowflake breach” usually means weak access controls at the customer, not a flaw in the platform.
How much has this hurt ASOS so far?
The market reacted fast. Reuters reported shares dropped more than 11% on Tuesday. Investing.com says they fell as much as 13.2% before paring losses to around 9%. The exact figure depends on when you check.
The exposure is large. ASOS has around 17 million active customers across more than 150 countries, according to City AM’s 2026 report.
This also isn’t ASOS’s first problem this year. In August 2026, ASOS US Sales LLC notified US customers that attackers had used credentials obtained outside the company to access accounts. A law firm’s investigation put the number at roughly 138,828 people. There’s no confirmed link to Tuesday’s alert.
Is this part of a wider run of UK retail attacks?
Yes, the timing fits a pattern. The April 2025 attacks on Marks & Spencer and the Co-op were assessed by the Cyber Monitoring Centre as a combined event costing £270 million to £440 million (2025).
A 2026 Marsh survey of 350 UK retail executives found that 95% say their business has significant areas of cyber exposure. Retailers hold a lot of personal data and have to keep trading, which makes them attractive targets.
What should ASOS customers do right now?
Most of the risk is in what happens next. GB News quoted a security expert who expects criminals to exploit the confusion. That means fake password-reset requests, payment confirmations, order updates and refund offers, sent by email, text or social media.
- Don’t tap the Telegram link or try to contact the sender. Experts quoted by Eastern Eye say the same.
- Don’t use links in messages. If you want to check your account, open the app or type the address yourself.
- Change your ASOS password if you’ve reused it anywhere, and fix those other accounts too. Start with your email.
- Turn on two-factor authentication where it’s offered, and use a password manager so every site gets a unique password.
- Check your card statements over the coming weeks. Report anything odd to your bank.
- Report scams. In the UK, forward suspicious emails to report@phishing.gov.uk and texts to 7726. In the US, report to the FTC at ReportFraud.ftc.gov.
ASOS itself publishes cyber security guidance. It says to avoid clicking links or opening attachments in emails you doubt.
If you’re a US customer who got the August account-access notice, the same rules apply, and a credit freeze is worth considering if you suspect identity misuse. eSecurity Planet suggests reviewing your credit reports and considering a fraud alert. [LINK: how to set up a password manager]
What happens next?
UK law puts pressure on ASOS. LBC notes that British companies must report data breaches to officials within three days and notify affected people quickly when the risk is high. If a breach is confirmed, expect a regulator filing and an email to customers. [LINK: what to do after a data breach notice]
Until then, treat any message about this as suspect, including ones that look like ASOS updates. If ASOS contacts you, it should be through the app or an email you can verify from the account itself.
Must check: 283 Dangerous Android Apps: Uninstall these apps immediately
FAQ
Has ASOS confirmed it was hacked?
No. A spokesperson told Reuters the company was aware of the reports but didn’t confirm or comment further. The site and app kept working, and ASOS hasn’t said what data, if any, was accessed.
Is my ASOS account safe?
We don’t know yet. Nothing public confirms customer accounts were exposed in this incident. Use a unique password and two-factor authentication, and avoid any link in a message about this. That covers you either way.
What does Snowflake have to do with ASOS?
The threatening notification claimed the attackers had “fully compromised” ASOS’s Snowflake instance. Snowflake is a cloud data platform used by many companies. ASOS hasn’t confirmed the claim, so it’s unclear what data, if any, was involved.
Should I delete the ASOS app?
You don’t have to. Deleting the app doesn’t remove your data from ASOS’s systems, and the notification itself isn’t dangerous unless you tap the link. If you’d feel safer, log out, and update the app when ASOS releases fixes.
How can I tell if an ASOS email is fake?
Be suspicious of anything about this alert, such as a refund, a forced reset or an unexpected order. Don’t click anything. Go to the app or type asos.com yourself to check your account.






