Data breach

ASOS data breach: what happened and what to do now

An alarming notification came from the real ASOS app. Here is what the retailer has confirmed, what remains unknown, and the steps that matter for customers.

Written by ProtectMyData Editorial. Published . Last updated . 8 min read

Original editorial illustration of an ASOS order card, a magnifying glass and a privacy shield. Not a screenshot of the incident.

Updates

7 October 2026: First report prepared. Checked the official ASOS announcement and updated reporting. Clearly separated possible access to names and contact details from unconfirmed claims about data theft and Snowflake.

What to know

  • ASOS confirmed an unauthorized customer notification and activity involving third-party communication platforms on 6 October.
  • Names and contact details may have been accessed. ASOS does not believe payment-card information or account passwords were impacted.
  • The attackers' claim about Snowflake, the number of affected customers, and the extent of any stolen data remain unconfirmed.
  • Do not follow the notification's external link. Open ASOS directly and be cautious about messages offering refunds, compensation or urgent security checks.

What happened at ASOS?

On Tuesday 6 October 2026, customers of the online fashion retailer ASOS received an unexpected push notification headed “ASOS HACKED.” The message was addressed to the company’s data protection officer and IT team. It claimed that a Snowflake instance had been compromised and threatened a leak unless ASOS engaged with the sender.

The important detail is that this was not simply an email impersonating a retailer. The notification arrived through the genuine shopping app. That makes the message particularly confusing: a channel customers normally associate with deliveries and offers was used to deliver an apparent extortion demand.

ASOS subsequently issued an official market announcement confirming that an unauthorized notification had been sent at around 10 am that day. It said it was investigating unauthorized activity involving third-party platforms used to communicate with customers, had restricted access to the notification platforms, and was working with specialist advisers and relevant authorities.

The company’s customer notice, reported by The Guardian and BleepingComputer, asked recipients to disregard the notification and not click or engage with its external third-party link. We are not reproducing that link here.

What is confirmed, and what is not?

A threatening message, a company statement and an attacker’s claim are different types of evidence. The official ASOS statement is the clearest source for the company’s position. It acknowledges the incident but does not establish every allegation made in the notification.

Unauthorized notification
ASOS confirmed that an unauthorized customer notification was sent on 6 October. Company statement
Third-party communication platforms
ASOS says it is investigating unauthorized activity involving platforms used to communicate with customers. Company statement
Names and contact details
ASOS says basic personal information, including names and contact details, may have been accessed. This is a possible exposure, not a confirmed list of stolen records. Company statement
Passwords and payment cards
ASOS does not believe these were impacted. That is the company's stated assessment, not a guarantee about every customer account. Company statement
Snowflake compromise
The notification's claim has not been confirmed by ASOS in the sources reviewed. Not established
Number of affected customers
No verified affected-customer count was disclosed in the sources reviewed. Not established
Extent of any data theft
The amount of information taken, the exact records involved and any release of those records are not established by the official announcement. Not established

What personal information could be involved?

ASOS’s wording is “basic personal information including name and contact details may have been accessed.” It does not provide a complete field-by-field inventory. Contact details can be useful to scammers, but the statement does not establish which particular email addresses, phone numbers or postal addresses were involved.

Do not turn that uncertainty into a claim that every ASOS customer has been affected. A retailer’s total customer base is not the same as the number of records exposed in an incident. Similarly, an alert appearing on your phone does not, by itself, prove that your individual information was stolen.

The distinction also matters for passwords and cards. The company says it does not believe those were impacted. You should respond to suspicious account activity and any information you personally entered on an unfamiliar page, rather than assume the notification proves your card or password was compromised.

What should ASOS customers do now?

Start with steps that reduce risk without requiring you to know the final scope of the investigation. There is no need to engage with whoever sent the threat or to pay anyone claiming they can check a leaked file.

  1. Ignore the external link in the notification Do not open the linked channel, reply to the sender or provide information. For updates, open the ASOS app yourself or type asos.com into your browser. The company has asked customers to disregard the unauthorized notification.
  2. Treat follow-up security messages cautiously Be wary of emails, texts or calls asking you to confirm payment details, reset your password through a supplied link, collect compensation or claim a refund. Visit the retailer independently instead. A familiar name, an order reference or a real-looking logo does not authenticate a message.
  3. Use a unique password ASOS does not believe account passwords were impacted. Even so, if you reuse your ASOS password elsewhere, replacing reused passwords with unique ones is sensible account hygiene. A password manager can help. Prioritize any account where you notice unfamiliar activity.
  4. Protect your email account Turn on two-step verification for your email account and other important services where available. Email often controls password resets for shopping and financial accounts. Do not share a one-time code with a caller or an unfamiliar website.
  5. Check activity and report real problems Review your recent ASOS activity and bank statements for transactions or changes you do not recognize. If money has been taken or card details were entered on a suspicious page, contact your bank through its official app or the number on your card. Follow the reporting guidance linked in Sources for your country.
  6. Follow verified updates Use ASOS's official announcements and reputable reporting. Early news stories can become outdated as investigations develop. Check the date and the wording of the original statement before sharing a headline or treating an attacker’s claim as confirmed.

Can you still use the ASOS app and website?

In its 6 October statement, ASOS said its website and app were operating as normal, with no current disruption to operations. That is the company’s published position. It should not be rewritten as an independent guarantee that no security risk exists.

If you need to check an order or contact support, navigate directly to the genuine service. Do not use the external link from the unauthorized alert, a sponsored search result you have not checked, or a message promising special access to breach information. Keep the app updated through your device’s official app store.

Why a shopping-app alert matters beyond shopping

This incident shows how a familiar communication channel can make an unfamiliar message appear credible. Shoppers normally expect an app notification to come from the retailer. Attackers can exploit that expectation to create urgency, even when the demand is aimed at the business rather than the customer.

Publicity around an incident can also give unrelated scammers a convincing story. A fraudulent message may refer to a real breach while asking you to complete a fake security check. A real news event does not make the message itself legitimate.

If personal contact information does circulate, it can be combined with other information already available online to make targeted messages more believable. That is a general privacy risk, not evidence that this has happened to a particular ASOS customer.

What a privacy scan can and cannot tell you

A free ProtectMyData scan is an optional way to check available exposure and breach evidence associated with an email address. It is not an ASOS-specific breach checker and cannot confirm that your details were part of this incident while the affected records remain unverified.

Likewise, requesting removal from public websites and data brokers is different from reversing a breach. Removal can help reduce public exposure, but it does not erase stolen copies of data or remove historical breach records. Changing compromised credentials and responding to fraud remain important separate actions.

You can read this report and use the official sources without running a scan or buying anything. The scan alongside the article is there if you want to understand more about your wider exposure.

How we checked this report

This report was checked on 7 October 2026 against ASOS’s official 6 October market announcement, BleepingComputer’s reporting and The Guardian’s updated coverage. The official announcement controls the wording of the company’s position; independently reported details are attributed rather than presented as our own investigation.

We have not obtained, downloaded or examined any alleged leaked customer records, and have not contacted the threat actor. No affected-customer count or confirmation of the Snowflake allegation is being inferred from app-user reports or the company’s total customer base.

We have not verified a Google Trends ranking or search-volume figure for this incident. Broad news coverage is evidence of public attention, not proof that a story is one of Google’s top searches. The source list and update notes below make the evidence behind this page explicit.

Timeline

  1. Customers receive an unauthorized alert

    The app notification headed “ASOS HACKED” claims a compromise and threatens a leak. ASOS's later announcement confirms the approximate notification time.

  2. ASOS issues an official statement

    The retailer confirms unauthorized activity involving third-party communication platforms, says names and contact details may have been accessed, and says it does not believe passwords or payment cards were impacted.

  3. Customers are told not to follow the link

    The company asks recipients to disregard the unauthorized push notification and not engage with its external link, as reported by The Guardian and BleepingComputer.

  4. This report is checked against current sources

    The affected-customer count, extent of any data theft and Snowflake allegation remain unconfirmed in the sources reviewed for this report.

Questions

Was ASOS hacked in October 2026?

ASOS confirmed an unauthorized customer notification and unauthorized activity involving third-party communication platforms on 6 October 2026. It said names and contact details may have been accessed. The full scope of the incident was not established in the sources reviewed.

Is this about ASUS or ASOS?

This report concerns ASOS, the online fashion retailer, not ASUS, the computer and electronics company.

Were ASOS passwords or payment-card details stolen?

ASOS said it did not believe account passwords or payment-card information were impacted. That is the company’s assessment, not evidence that every other type of information was unaffected.

How many ASOS customers were affected?

A verified affected-customer count had not been disclosed in the sources reviewed on 7 October 2026. The retailer’s total customer base must not be used as a breach count.

Did the attackers compromise Snowflake?

The unauthorized notification claimed that a Snowflake instance had been compromised. ASOS's official announcement did not confirm that allegation. It should be treated as an attacker claim, not an established technical finding.

Does receiving the notification mean my data was stolen?

No. Receiving the alert establishes that a notification reached your device. It does not establish whether your individual records were accessed or stolen.

Can a free scan confirm I was in this ASOS incident?

No. ProtectMyData’s scan can show available exposure and breach evidence, but it cannot verify your involvement in this particular incident while the affected records remain unconfirmed.

Sources

  1. Update regarding cyber incident

    ASOS plc, official RNS announcement, 6 October 2026

  2. ASOS confirms data breach after “HACKED” in-app notifications

    BleepingComputer, 6 October 2026

  3. Asos warns customer data may be compromised after ‘unauthorised’ app access

    The Guardian, 6 October 2026

  4. Phishing: how to report suspicious messages

    UK National Cyber Security Centre, Practical reporting guidance

  5. Report a scam

    Scamwatch, Australian National Anti-Scam Centre, Practical reporting guidance

  6. Report fraud

    US Federal Trade Commission, Practical reporting guidance

All news