
ASOS customers received a message through the retailer’s own app on Tuesday that appeared to be a warning from hackers. A day later, the clearest picture is narrower than the alarming notification suggested, but serious enough that shoppers should stay alert: ASOS says basic personal information, including names and contact details, may have been accessed.
In a statement to the London Stock Exchange, the UK online fashion retailer confirmed that an unauthorised notification was sent at around 10am on October 6. It said it was investigating unauthorised activity involving third-party platforms used to communicate with customers, had restricted access to its notification systems and was working with specialists and relevant authorities.
The message claimed that an ASOS Snowflake instance had been compromised and threatened to leak data. That remains the sender’s claim, not an established finding. ASOS has not confirmed that its Snowflake environment was breached or said how many customer records, if any, were taken. A push notification arriving from a familiar app shows that someone gained access to a trusted communication channel; it does not, by itself, prove access to every system named in the message.
ASOS says it does not believe payment-card information or account passwords were affected. Its website and app have remained operational, and it says there is no current disruption to its business. Those assurances are important, but the investigation is ongoing, and the company has not yet identified the full scope of the possible exposure. The distinction between ‘may have been accessed’ and confirmed data theft matters when customers are deciding what to do next.
For shoppers, the immediate risk is not limited to whether a card number was taken. Names and contact details can make a fake delivery problem, refund offer or account-security warning sound convincing. This is especially awkward when the first alarming message arrived through a channel customers normally trust. A recent third-party messaging breach involving Trezor illustrated how attackers can turn a brand’s own communications into a phishing opportunity even without reaching the product’s core security systems.
The UK National Cyber Security Centre advises ASOS customers to watch for suspicious messages, avoid links in unexpected push alerts, emails or texts, and use strong, separate passwords with two-step verification where available. Anyone receiving a message about an ASOS order or account should open the app or website directly, rather than follow a link in the message. A request for a password, one-time code or card details deserves particular suspicion.
There is no need to assume a password was stolen simply because the app alert appeared. Customers who reused their ASOS password elsewhere should still change that reused password, and everyone should review their account for unfamiliar activity. ASOS says it will provide a further update if the situation changes. Until then, the responsible reading of this incident is straightforward: an unauthorised message was sent, some contact information may have been exposed, and the attackers’ larger database claim is still unverified.







