The ASOS hack claim surfaced on Tuesday, 6 October 2026, when thousands of app users received a push notification saying hackers had “fully compromised” the retailer’s Snowflake data platform.
According to The Guardian, ASOS is understood to still be investigating whether any hack has taken place after the alert reached customers, while the retailer’s website and app kept operating normally.
The message, which also linked to a Telegram channel, read:
“Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
What is the ASOS hack claim?
The message is addressed to the company’s DPO, or data protection officer, the person who oversees personal data, and it names Snowflake, a cloud platform where companies store and analyse databases.
A push notification is a message sent to a phone through an app, so being able to send one matters. Jake Moore, a global cybersecurity adviser at ESET, said:
“The fact the hackers managed to send a push notification to customers suggests they have gained access to at least some of ASOS’s connected systems, but it doesn’t prove their full claims about the extent of the data breach.”
What has ASOS said about the ASOS hack?
An ASOS spokesperson said the company was aware of the reports but did not confirm or comment further. The claim is unverified, and ASOS has not said how many customers could be affected.
Its shares fell more than 11% on Tuesday, after rising more than 60% so far this year. Reports say it serves about 17 million customers across more than 150 countries.
What should customers do now?
Security experts advised customers not to click the Telegram link in the notification and to treat unexpected messages asking for passwords or payment details with suspicion. Dray Agha, a senior security manager at Huntress, said:
“I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.”
ASOS’s earlier breach and what happens next
ASOS disclosed a separate incident earlier this year, after it detected unusual account activity on Tuesday, 28 July 2026.
Attackers reused passwords stolen from other services, a method known as credential stuffing, and a law firm notice put the number of affected people at about 138,828.
Under UK data protection rules, a confirmed breach must be reported to the Information Commissioner’s Office within 72 hours. A similar leak threat played out in the Canvas ransom deadline, while Meta said there was no breach when Instagram users were flooded with password reset emails.
Sources
- The Guardian via DataBreaches.net, ASOS customers receive hack notification threatening leak
- Cybernews, Asos data breach: Hackers threaten leak via app message
- Irish Examiner, Asos investigating after thousands of customers get notification saying retailer has been hacked
- Eastern Eye, ASOS hacked? Customers receive alarming data breach alert
- Reuters via Global Banking and Finance, ASOS shares fall over 11% following hack reports
- PinkNews, ASOS users issued warning as app hacked and threatening message appears
- CyberInsider, ASOS credential stuffing attack exposed data of 138,828 customers
- eSecurity Planet, ASOS account takeover attack exposes data of 138,828 customers
- Swisher Post, Chick-fil-A data breach hits loyalty rewards accounts
- Swisher Post, ShinyHunters give Instructure until tomorrow to pay up as Canvas ransom deadline hits
- Swisher Post, Instagram password reset emails flood users as Meta says no breach





