BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident

ASOS has confirmed a cyber incident involving third-party platforms it uses to communicate with customers. The online retailer says basic personal information, including names and contact details, may have been accessed after an unauthorized push notification was sent through its customer app.

What happened

On October 6, 2026, some ASOS customers received an unauthorized mobile-app notification claiming that hackers had compromised an ASOS Snowflake environment. The message demanded contact with the company and threatened to leak data.

ASOS subsequently confirmed that it is investigating unauthorized activity involving third-party customer-communication platforms. The company restricted access to the affected platforms and brought in internal and external specialists while working with relevant authorities.

What ASOS has confirmed

ASOS says basic personal information such as customer names and contact details may have been accessed. The company does not currently believe payment-card information or account passwords were affected.

The ASOS website and app remained operational, with no reported interruption to shopping or other business operations. ASOS said it was too early to quantify any possible financial or trading impact.

What remains unverified

A group calling itself the Xuanye group claimed responsibility and said it had compromised an ASOS Snowflake instance. That specific claim has not been confirmed by ASOS.

Snowflake told Reuters that its investigation had found no compromise of the Snowflake platform. That statement does not establish whether credentials or systems belonging to an individual Snowflake customer were accessed. The method of entry, the number of affected people, and the exact data taken remain unknown.

Who may be affected

ASOS customers whose names or contact details were stored in the affected communications platforms may be exposed. ASOS has not disclosed a confirmed victim count or a complete list of affected data fields.

Because the attackers demonstrated access to a legitimate customer-notification channel, customers should be cautious about follow-up messages that appear to come from ASOS. Stolen contact details can make phishing attempts more convincing even when passwords and payment cards are not exposed.

Why this incident matters

The incident highlights third-party platform risk. Businesses often use separate providers for customer messaging, analytics, cloud data, and mobile notifications. Access to one connected service can create a trusted route to customers even when the primary website continues operating normally.

For small businesses, the lesson is not limited to retail. Any provider that can send email, text messages, or app notifications under a company’s name should be treated as a high-impact account and protected accordingly.

Practical defensive actions for ASOS customers

Do not act on the unauthorized alert

Do not use links, Telegram channels, or contact instructions contained in the push notification. Use the ASOS website or app opened directly, not through a message link, for account activity.

Watch for targeted phishing

Be suspicious of emails, texts, and calls referencing the incident, refunds, delivery problems, password resets, or account verification. Verify requests through an independently obtained ASOS support channel.

Protect reused credentials

ASOS says passwords are not believed to be affected. Customers who reused their ASOS password elsewhere should still replace reused credentials with unique passwords and enable multifactor authentication on email and financial accounts.

Review financial activity

ASOS says payment-card information is not believed affected. Customers should nevertheless continue routine monitoring of bank and card accounts and report unfamiliar activity directly to the financial institution.

Defensive actions for businesses

Secure customer-communication platforms

Require multifactor authentication, separate administrator accounts, least-privilege access, and rapid offboarding for marketing, messaging, and mobile-notification services. Review which integrations can send messages using the company name.

Audit third-party connections

Inventory cloud data, analytics, customer engagement, and notification providers. Remove unused API keys and integrations, rotate long-lived credentials, and restrict access by role and network location where supported.

Prepare to revoke messaging access quickly

Incident-response plans should include procedures for disabling a compromised notification provider, preserving audit logs, warning customers through verified channels, and coordinating with vendors and authorities.

Sources

Reuters: ASOS confirms unauthorized activity and possible customer-data access

BleepingComputer: ASOS confirms data breach after unauthorized notifications

Financial Times: ASOS investigates cyber incident

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment