- ASOS customers received a notification titled “ASOS HACKED”.
- The message claimed attackers had compromised a Snowflake instance and threatened to leak data.
- ASOS has not confirmed the extent of any alleged breach.
Thousands of ASOS customers were sent an alarming notification on Tuesday morning claiming that the online fashion retailer had been hacked.
The message, titled “ASOS HACKED”, appeared to be written by the alleged attackers and was delivered through the ASOS app. It was addressed to the company's data protection officer and IT team.
“Dear Asos DPO and IT, we have fully compromised the Snowflake instance,” the message said. “Engage with us, or we will leak it.”
It also contained a link to a Telegram chat.
The incident has raised concerns about whether attackers gained access to ASOS's systems and were then able to use its customer notification infrastructure to broadcast their message. However, the notification alone does not establish how much data may have been accessed or whether the attackers' wider claims are genuine.
Reuters reported that it was unable to independently verify the reports. ASOS acknowledged awareness of the reports but did not confirm that it had suffered a breach.
What did the ASOS hacked notification say?
The message claimed that attackers had “fully compromised the Snowflake instance”, referring to Snowflake, a cloud-based data platform used by businesses to store and analyse large volumes of information.
It then threatened to release the data unless ASOS engaged with the attackers through Telegram.
The notification appears to have reached a large number of users. More than 400 people had reported problems involving ASOS to Downdetector by around 10.30am, although those reports do not establish the number of people who received the message or the scale of any potential data breach.
Cybersecurity experts have urged customers not to click the Telegram link or attempt to contact the alleged attackers.
Jake Moore, global cybersecurity adviser at ESET, said the ability to broadcast a message directly to app users suggested that the attackers had gained access to at least some of ASOS's connected systems.
However, he stressed that this did not prove their claims about the extent of the breach.
“The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS’s connected systems, but it doesn’t prove their full claims about the extent of the data breach,” Moore said.
He added that the attackers could be using the notification to put pressure on ASOS and demonstrate their apparent access in an attempt to secure a ransom.
Has ASOS confirmed the data breach?
Not at this stage.
ASOS has acknowledged reports about the incident but has not confirmed that its Snowflake environment was compromised or that customer data was stolen. The number of customers potentially affected and the type of information that may have been accessed are also unknown.
That distinction is important because a successful intrusion into one part of a company's technology infrastructure does not automatically mean that all customer data has been accessed or extracted.
ASOS has around 17 million customers a year across more than 150 countries, making the potential impact significant if customer information has been compromised.
The incident has also had an immediate financial impact. ASOS shares fell by more than 11 per cent on Tuesday following reports of the alleged hack, although the exact extent of the company's losses in relation to the incident remains to be seen.
For customers, the safest response is to avoid the Telegram link, watch for suspicious emails or messages claiming to be from ASOS, and be cautious about requests for passwords, payment information or account verification.
Under UK data protection rules, organisations must report certain personal-data breaches to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If a breach is likely to create a high risk to individuals, affected people must also be informed without undue delay.
For now, the biggest unanswered question is not whether ASOS customers saw the message. They clearly did. It is how far the attackers actually got inside ASOS's systems, and whether any customer data was taken.








