Search

ASOS Hack: What Happened and What Customers Should Do

ASOS Hack: What Happened and What Customers Should Do

ASOS confirmed a data breach on Tuesday 6 October 2026 after hackers hijacked its mobile app to send customers a push notification headed "ASOS HACKED". Names and contact details may have been accessed, the retailer says, but payment cards and passwords are not thought to be affected. Here is what we know so far, and what to do if you have an ASOS account.

Also Read: Why Unicode Exists (and Why Emojis Break Things) - How To's

What happened in the ASOS hack

At around 10am UK time, ASOS app users received an alert that did not come from the retailer. The message addressed ASOS's data protection officer and IT team, claimed the attackers had fully compromised the company's Snowflake data platform, and threatened to leak data unless ASOS made contact. It also carried a link to a Telegram channel.

Also Read: Write-Ahead Log (WAL): How Databases Survive Crashes

Screenshots spread across Reddit and social media within minutes. BleepingComputer reports that the alert appears to have reached many, if not all, mobile app users. Investors reacted too: ASOS shares closed down 10.6% at 449p.

Also Read: News and Ofcom Meta investigation

What ASOS has confirmed

In a statement published by Computer Weekly, ASOS said it is investigating unauthorised activity on the third-party platforms it uses to communicate with customers. So far the company says:

  • Basic personal information, including names and contact details, may have been accessed.
  • Payment card information and account passwords are not believed to be affected.
  • Access to its notification platforms has been restricted.
  • The website and app are running normally.

ASOS has not said how many customers are affected, and it has not confirmed the Snowflake claim. Snowflake says it is investigating and has found no evidence so far that its own platform was compromised. Under UK data protection law, ASOS has three days to report a breach to regulators.

Also Read: How Much More Do AI News Engineers Actually Make in 2026?

Who is behind the ASOS data breach?

The Telegram channel belongs to a group calling itself Xuanye Group, which security researchers had not seen before today. The group claims it holds customer data, that payment information was not taken, and that it will hold the data back for a set period. It has published no proof.

Also Read: News: Nvidia Nears a

That matters. Boris Cipot of Black Duck told Computer Weekly that sending a push notification does not prove access to the data platform behind it. ESET's Jake Moore said the public alert looks like a pressure tactic to force a ransom negotiation. Treat the attackers' claims as unverified until ASOS publishes its findings.

Also Read: OpenAI Apologises After AI Agents Breach Australian Sites

The second ASOS security incident in three months

Today's breach follows a separate incident in July 2026, when attackers used passwords stolen elsewhere to log in to ASOS accounts. That credential-stuffing attack affected an estimated 138,828 US customers. Nothing so far links the two incidents, but together they put ASOS's account security under scrutiny.

What ASOS customers should do now

  1. Do not tap the notification or its link. ASOS is telling customers to ignore the alert.
  2. Change your ASOS password, and change it anywhere else you reused it. ASOS's own cyber security advice recommends a unique password for every account.
  3. Watch for phishing. Scammers will use the news to send fake ASOS refund, delivery and "verify your account" messages. Names and contact details make those messages more convincing.
  4. Check whether your email appears in other breaches at Have I Been Pwned.
  5. Monitor your bank and card statements, even though ASOS says card data was not affected.

Talion's Natalie Page noted that ASOS does not enforce multi-factor authentication (MFA). Signing in with a Google or Apple account that has MFA switched on adds a layer of protection.

What developers and online store owners can learn

The attackers did not need to break the ASOS app. They needed access to a tool allowed to message its users. For anyone running an eCommerce site, that is the lesson: every marketing, analytics and notification platform you connect is part of your attack surface.

This story is still developing. Follow our Latest News section or subscribe to the newsletter for updates.

TWT Staff

TWT Staff

Writes about Programming, tech news, discuss programming topics for web developers (and Web designers), and talks about SEO tools and techniques

Your experience on this site will be improved by allowing cookies Cookie Policy