Shoppers who use the ASOS mobile app got an unwelcome surprise on the morning of October 6, 2026, when a push notification appeared on their phones under the blunt heading “ASOS HACKED.” The message was not from ASOS marketing — it was planted by an attacker who had found a way into the retailer’s customer-messaging infrastructure, and it set off a scramble inside the company to figure out exactly what had actually been touched.
A Notification Channel Turned Into a Megaphone
According to details that have emerged since the incident, the rogue notification was addressed directly to ASOS’s data protection officer and IT staff, demanding they “engage” with the attackers or risk having stolen data leaked. It included a link to a Telegram channel and asserted that the group had “fully compromised” ASOS’s Snowflake environment, the cloud data platform many large retailers use to warehouse customer and sales information.
ASOS has confirmed that something real did happen, but it has been careful to separate confirmed fact from the attacker’s own claims. The company says it is “investigating unauthorised activity involving third-party platforms that we use to communicate with customers” and that it immediately cut off access to the notification system once the rogue message was spotted. Beyond that, ASOS has only confirmed an “unauthorised customer notification” — not a verified breach of its Snowflake instance.
What Data Might Be Exposed — and What Probably Isn’t
ASOS has said that basic personal details, such as customer names and contact information, may have been accessed through the compromised notification platform. Importantly, the retailer states it does not believe payment card numbers or account passwords were affected by this particular incident. That is a meaningfully different exposure profile than a full database theft would represent, assuming the assessment holds up under further investigation.
Security researchers who reviewed the incident have urged caution about taking the attacker’s framing at face value. A spokesperson from Check Point told reporters that the group behind the message may simply be trying to pressure and embarrass ASOS into contact, rather than demonstrating genuine access to backend systems. Gaining control of a third-party notification tool does not, by itself, prove an attacker also reached ASOS’s cloud data warehouse, payment systems, or core retail network — those would typically require separate footholds.
Not ASOS’s First Rodeo This Year
This is the second publicly disclosed security incident to hit ASOS in a matter of months. Back in late July 2026, the company confirmed that customer accounts had been accessed using login credentials obtained from outside the company — a classic credential-stuffing attack, where criminals reuse username and password combinations leaked from unrelated breaches to try their luck against other sites. That episode, detected on July 28 and confirmed the next day, reportedly exposed names, addresses, phone numbers, dates of birth, and partial card details such as expiration dates and the last four digits of payment cards.
ASOS responded to the July incident by locking affected accounts, forcing password resets, and blocking or reversing suspicious transactions. There is no confirmed link between that earlier credential-stuffing wave and this month’s notification-platform compromise, but the back-to-back nature of the incidents has put additional scrutiny on the retailer’s third-party vendor relationships and its broader security posture.
Market and Customer Fallout
The financial market reaction was swift: ASOS shares reportedly fell more than 11%, with some intraday trading showing declines approaching 13%, as the news of a public “hacked” notification spread faster than the company’s own clarifications. ASOS has stated its website and app continued operating normally throughout, and it has cybersecurity and business continuity insurance in place with a major global insurer, though it says it is too early to gauge any impact on trading performance.
What Customers Should Do Now
Security teams and consumers alike should treat this as a reminder that a dramatic-looking notification is not, on its own, proof of a specific type of compromise. ASOS customers are advised to:
- Avoid clicking the Telegram link referenced in the rogue notification, and ignore any follow-up messages that try to leverage the incident to request passwords or payment information.
- Watch official ASOS channels for verified updates rather than relying on screenshots circulating on social media.
- Change their ASOS password if they have reused it anywhere else, and enable unique, strong passwords going forward.
- Monitor bank and card statements for unusual activity, even though ASOS says payment data is not believed to be affected.
ASOS says it is working with external specialists and relevant authorities to determine the scope of the incident. Until that investigation concludes, the gap between what attackers claim and what has actually been verified remains the central open question — one that will likely shape how seriously regulators and customers treat the retailer’s next update.
Leave a Reply
You must be logged in to post a comment.