ASOS Hack: Customers Get 'ASOS HACKED' Alert | Update

ASOS hack: Customers received 'ASOS HACKED' push alerts on 6 Oct 2026 claiming a Snowflake compromise. Names and contact details may be exposed. Learn what to do next.

ASOS Hack: Customers Get 'ASOS HACKED' Alert | Update
Share
Share this article Choose a network or an app on your device.
Email

Edition: EN

What Happened in the ASOS Hack?

The British fashion retailer ASOS is investigating a possible ASOS hack after thousands of app users received a threatening push notification on 6 October 2026 titled "ASOS HACKED". The message, addressed to the company's data protection officer and IT team, claimed attackers had "fully compromised the Snowflake instance" and threatened to leak customer data unless the retailer engaged with them. The incident sent ASOS shares down more than 10% and raised fresh questions about supply-chain security in e-commerce.

At around 10:00 BST on Tuesday, customers of the popular fashion app began sharing screenshots of a hostile push notification that appeared to come from ASOS itself. The message read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." It included a link to a Telegram channel run by a group calling itself "Xuanye" or "Xuanye Group".

ASOS later confirmed that an "unauthorised customer notification" had been sent through a third-party communication platform. The company immediately restricted access to its notification systems and launched an investigation. Its website and app remained fully operational, suggesting the attackers had not disrupted core services.

What Is Snowflake and Why Does It Matter?

Snowflake is a cloud-based data platform used by thousands of businesses to store and analyse large volumes of information. In this context, a claimed Snowflake compromise is significant because it could expose sensitive customer records. However, Snowflake quickly pushed back, saying it had found "no compromise of the Snowflake platform." Security analysts note that the 2024 Snowflake attacks on Ticketmaster were traced not to a platform flaw but to stolen customer credentials and missing multi-factor authentication.

What Data May Have Been Affected?

ASOS said basic personal information, such as names and contact details, may have been accessed. Crucially, the company does not believe payment-card data or account passwords were compromised. ASOS has 17 million customers across more than 150 countries, and in 2025 it generated revenue of £2.5 billion (about €3 billion). The retailer is popular in the Netherlands and across Europe.

The UK's National Cyber Security Centre (NCSC) is assisting ASOS with the investigation, and the company is expected to report the incident to the Information Commissioner's Office within the 72-hour GDPR window.

How Does This Compare to Other Recent Cyberattacks?

The ASOS hack is the latest in a string of high-profile retail and public-sector breaches. In 2024, Snowflake-linked attacks affected Ticketmaster and AT&T, exposing hundreds of millions of records. Just a day before the ASOS alert, hackers stole names, addresses and national identification numbers of about 8.8 million people from Denmark's population register. Last week, grocery delivery firm Flink was also targeted, with attackers demanding payments from individual customers.

Unlike traditional retail data breaches that quietly exfiltrate data, the ASOS attackers chose a highly public extortion tactic — weaponising the retailer's own push-notification channel to pressure executives. Cybersecurity experts in supply chain threat intelligence warn that public extortion often reduces the likelihood of a ransom being paid, but it can trigger phishing waves against customers.

What Should ASOS Customers Do Now?

  • Do not click the Telegram link or interact with the "Xuanye" channel.
  • Change your ASOS password immediately, especially if you reuse it on other sites.
  • Enable two-factor authentication on your ASOS account and email.
  • Watch for phishing emails, texts or calls that reference the ASOS hack.
  • Monitor bank and card statements for suspicious activity.

Frequently Asked Questions

Was ASOS actually hacked?

ASOS has confirmed an unauthorised customer notification and possible unauthorised access to names and contact details, but it has not confirmed the claimed Snowflake compromise.

Is my ASOS password at risk?

According to ASOS, account passwords are not believed to have been compromised. However, experts still recommend changing your password as a precaution.

Who is behind the ASOS hack?

A previously unknown group calling itself "Xuanye" or "Xuanye Group" has claimed responsibility via Telegram. Attribution has not been verified, and the tactic resembles attention-seeking actors like ShinyHunters.

Should I delete the ASOS app?

No. The app and website remain operational, and the notification was sent through a third-party communication platform. Simply ignore the malicious message and update your credentials.

What has Snowflake said?

Snowflake said it found no evidence that its platform was compromised, though it did not rule out issues with individual customer environments.

Closely related