
Asos appears to have been hacked, with customers sent a bizarre, threatening notification.
Users of the app received a message on Tuesday morning indicating that the company’s systems had been compromised.
“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message, apparently written by the cyber attackers, reads. “Engage with us, or we will leak it,” it continues, before linking out to a Telegram chat.
DPO refers to the data protection officer, the appointed person in a company who takes responsibility for safeguarding customers’ information. Snowflake is an online data platform used by a wide array of companies.
Asos did not immediately respond to a request for comment. It is also yet to post about the notification or possible cyber attack on its social media accounts.
It is not clear how many customers the notification was sent to. But it appears to have been delivered to at least a large number of the app’s customers.
Asos says that it has 17 million customers each year, in more than 150 countries. That was down slightly on last year, when 19.7 million people shopped on the site.
It reported revenues of £2.5 billion in 2025, down from £2.9 billion the year before. That led to an operating loss of £212 million last year.
Asos's statement doesn't help share price – but doesn't harm it either
The stock market seems neither perturbed nor buoyed by Asos’s statement. The share price is still down around 11 per cent over the day – it fell soon after the notification came out, and has been stuck there ever since.
Andrew Griffin6 October 2026 15:56
Asos finally responds to hack
More than five hours after the notification was sent, Asos has finally responded. It says that personal information may have been accessed in the cyber attack.
“ASOS can confirm that, at around 10am today, an unauthorised customer notification was sent to ASOS customers,” Asos said.
“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.
“Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.
“Our website and app are operating as normal, with no current disruption to any aspects of our operations.
“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.
“The Company has cyber security insurance with a large global provider, including business continuity insurance. It is too early to quantify any potential impact on trading.”
Andrew Griffin6 October 2026 15:37
Push notifications are one of the 'hardest-working channels' – but could this undermine trust?
The website might still be up – but it is important that users continue to trust push notifications, said one marketing expert, and that could be undermined by the worrying update this morning.
“Asos’s website never went down, but the commercial damage can start the moment customers lose trust in the messages coming through its own channels. People let a brand onto their phone because they trust it. Once that channel has been used to threaten them, they may start questioning genuine messages too,” said Marty Bauer, ecommerce expert at marketing company Omnisend.
“Push notifications are one of the hardest-working channels retailers have. Across brands using Omnisend, push automations had a 22.9% conversion rate last year. If customers now switch notifications off or stop engaging with them, that could have a direct impact on repeat sales.
“The first practical step is to pause any automated promotional sends. A discount arriving before an explanation of that notification risks making customers feel their concerns are being ignored.
“With Black Friday approaching, Asos will want existing customers to feel comfortable buying again. If shoppers disengage from push notifications and email now, that is revenue the brand may find difficult to win back.”
Andrew Griffin6 October 2026 15:08
Asos chatbot says company is 'currently investigating'
There is still no official comment from Asos about the apparent hack, but the online chatbot on the company’s website has said that the incident is under investigation.
The bot said: “We’re aware of the notification and are currently investigating. We son’t have any further information to share at this stage, but we’ll provide an update as soon as we know more.”
Anthony Cuthbertson6 October 2026 14:15
What is happening at Asos?
We’ve heard from Matt Hull, VP of Cyber Intelligence and Response at the cyber security company NCC Group, about what is happening at Asos and what the company should be doing next:
While the nature and extent of the reported incident remain unclear, the immediate priority for any organisation responding to a suspected cyber attack is containment. Before a business can return to normal operations, it needs to be confident that the attacker’s access has been identified and cut off.
Incident responders need to establish how the attacker gained access, which accounts and systems may have been compromised, what they were able to reach and whether they have other routes back into the environment. The decision to keep systems running or take them offline should be guided by the forensic evidence.
Asos are likely to be juggling a huge amount behind the scenes. The important thing is to communicate to customers and stakeholders what they know when they know it, be clear about what is still uncertain, and avoid leaving customers or other stakeholders guessing. Cyber incidents are rarely resolved in hours. Understanding the full scope of an attack, containing the threat and making sure an attacker cannot return can take days or weeks. Recovery comes once those stages have been worked through and the organisation can be confident that it is secure enough to operate normally again.
Matt Hull, VP of Cyber Intelligence and Response at NCC Group
Anthony Cuthbertson6 October 2026 13:36
Asos still yet to publicly acknowledge threatening notification
After this morning’s notification, seemingly sent by hackers, Asos has remained silent on the attack. Its website and app appear to still be operating as normal, and the company is yet to make any public statement about the incident.
Andrew Griffin6 October 2026 12:54
Asos share price plunge seems to stabilise
Asos’s valuation has been plunging since around 10am local UK time, just after the notification hit users’ phones. It fell for about an hour and then seemed to stabilise – and the initial impact of the cyber attack now seems to have been digested, with the share price down around 13 per cent since this morning.
Andrew Griffin6 October 2026 12:50
Cyber attack could endanger customers for 'months to come'
We still don’t know what data – if any – was compromised in the hack. But if the attackers got access to customers’ information, then the effects of the hack could last for “months”, a cyber security expert has warned.
“If customer information has been exposed, criminals could turn it into convincing scams for months to come. A fake delivery charge or refund message can feel credible when it includes your personal details; one visit to a fraudulent payment page could then hand criminals your card details,” said Gavin Millard, vice president of product at security firm Tenable.
“Customers should be wary of unexpected messages asking for payment or personal information, and check any request through the retailer’s official website or app. Businesses need to establish what has been accessed and communicate clearly, so customers know what to watch for.”
Andrew Griffin6 October 2026 12:49
Who are the hackers?
In the notification sent to users, hackers did not identify themselves. But they included a link to a Telegram chat, created today, that appears to identify them as “Xuanye Group”.
That is not a well-known hacking group and there is no indication they have been involved in any cyber attacks in the past.
The group did not make any specific demand in the channel, to Asos or anyone else, despite the suggestion in the push notification that it was threatening the company. And it also claimed that financial data had not been affected – though of course there is no particular reason to trust that assurance.
As below, experts really urge users not to click through on that link, the notification, or anything else that might come from the hackers.
Andrew Griffin6 October 2026 12:08
What should customers do now?
Here’s some more advice from experts about what to do if you’ve received the notification, or are generally concerned about the possible hack on Asos. The short version is: we don’t really know enough about what happened to be specific, but don’t panic, and there are important ways to be careful that will help you either way.
“Getting a message like that from an app you trust is genuinely unsettling. Most people think of a hack as something that happens out of sight, so seeing a threat land on your own phone makes it feel much more personal. It's completely understandable that people are worried, but the most important thing right now is not to panic. At times like this, panic can make matters much worse,” said Pete Membrey, chief research officer at ExpressVPN.
"The truth is we don't know much yet, and 'don't know' means don't know. A knee-jerk reaction could be exactly the wrong thing to do. What people can do is some simple due diligence. Don't tap on the notification or follow the link in it. Go to the ASOS website directly, by typing in the address yourself rather than through an email or the app, and reset your password. If the attackers have compromised that side of things, they may already have your old password, and if they're still inside they could potentially see the new one too. But it's a quick, simple step that should, in general, draw a line under it.
"What's more critical is everywhere else you've used that password. Everyone knows they shouldn't reuse passwords, but it happens. Maybe you needed to set something up in a hurry, or there's an old account you never got around to updating. If attackers have your password, you can guarantee they'll try it in every lock they can find. Without a password manager, that could take them about five minutes.
"So take this as a wake-up call to finally get a password manager and start updating your passwords. If nothing was leaked, great, you've still massively upgraded your security against future attacks. And if it was, you've slammed the door shut before anyone could take advantage. Either way, it's a win-win."
(You’ll find more advice and expert reaction below.)
Andrew Griffin6 October 2026 11:47