Online fashion retailer ASOS has confirmed it is investigating unauthorised activity involving third-party platforms used to communicate with customers after an unauthorised notification was sent through its customer communications channels. The company said basic personal information, including names and contact details, may have been accessed but it does not believe payment-card information or account passwords were affected.
ASOS has confirmed it is investigating a cyber-incident involving third-party platforms used to communicate with customers after an unauthorised customer notification was sent at around 10am on October 6.
The online fashion retailer said it took immediate action to restrict access to the affected notification platforms and is working with internal and external specialist advisers and relevant authorities.
In a statement, ASOS said: “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted.”
The company said its website and app are operating normally, with no current disruption to its operations.
ASOS added: “Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”
The incident first became apparent after ASOS customers received an unauthorised notification which included claims that the retailer had been compromised.
While ASOS has now confirmed the unauthorised activity, its statement does not confirm the wider claims made in the notification or provide details about how the third-party platforms were accessed.
Natalie Page, Head of Threat Intelligence at Talion Cyber Security, welcomed ASOS’s decision to publicly address the incident but warned customers to remain cautious while investigations continue.
“As a priority, ASOS must now work internally to understand the scale of the incident, and whether customer data has been impacted so they can inform impacted parties.
“At this time, it is still recommended customers of ASOS use caution online. Avoid clicking on links in messages from unknown senders, be wary of app notifications and avoiding sharing personal and financial information with unknown senders.
“Other attackers will likely jump on the incident to send out malicious communications, so customers of ASOS should be aware of this social engineering tactic.
“Updating passwords on ASOS accounts is also advisable, plus on any other accounts that share the same password.”
Cybersecurity experts had earlier warned customers to remain vigilant while the nature and extent of the incident were being established.
Dray Agha, Senior Manager of Security Operations at Huntress, said: “Snowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the ASOS mobile app also. This is clear public extortion. Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.”
Charlotte Wilson, Head of Enterprise for the UK & Ireland at Check Point, said: “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note. The fact ASOS shares fell by almost 5% within minutes of the reports emerging is a reminder that cyber security is now inseparable from commercial performance and corporate reputation. Before the company had even publicly established what had happened, investors were already pricing in the potential consequences.
“Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company. The fact that an attacker may have been able to hijack that relationship and send a threat directly to customers demonstrates how quickly a cyber incident can move from the server room to the front page, and then straight into the market value of a business. The reference to Snowflake will understandably raise questions about customer data, but we should be careful not to speculate about what has actually been accessed until ASOS has established the facts. Right now, the priority will be containing the intrusion, understanding exactly which systems and data have been compromised and closing off any continuing access.”
Wilson also warned customers to be alert to potential follow-on phishing attempts.
“For customers, the biggest immediate risk may be what happens next. Criminals know people will be searching for information about the ASOS hack, and we would expect attempts to exploit that confusion. Customers should be extremely suspicious of emails, texts or messages claiming their ASOS account has been compromised, offering refunds or asking them to reset passwords through a link. Go directly to the ASOS app or website rather than following links sent to you.”
Jamie Akhtar, CEO and Co-founder of CyberSmart, said: “One possibility is that attackers gained access to a system used to send customer notifications and broadcast an extortion demand to put pressure on ASOS. However, if hackers have managed to gain access to more of the ASOS systems than just their app notifications then the impact could be severe for ASOS themselves, customers and third-party businesses. For customers, the immediate impact is uncertainty and concern, alongside reported website issues. If personal information has been accessed, it could enable more convincing phishing attempts and fraud. Customers should avoid clicking the link in the notification and check ASOS’s official website directly for updates.”
ASOS said it has cybersecurity insurance with a large global provider, including business continuity insurance. The retailer said it remains too early to quantify any potential impact on trading.

