ASOS admits that “basic personal information” may have been accessed in cyberattack

6 Oct 2026
Image © Adobe Stock

ASOS has confirmed that the message received by some customers on the morning of 6 October was an “unauthorised customer notification” and that “basic personal information may have been accessed”. However, it said that it does not believe that payment-card information or passwords have been accessed by the hackers.

Thousands of its mobile app users and customers received a pop-up message purporting to be from hackers, stating that they have “fully compromised the Snowflake instance” and warning ASOS to engage with them or they will leak it.

Snowflake is a data storage company, and the hackers appeared to be threatening to leak ASOS customer data. Snowflake told Sky that the company is investigating the hack. “As soon as we became aware of the notification that is currently being reported, we began an investigation,” a spokesperson said. “At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously. The investigation is ongoing and we will provide further updates as soon as more information becomes available.”

Reputational and financial damage

Shares in ASOS fell as much as 15% over the course of 6 October following reports of the possible data breach. With some customers complaining about the slowness of ASOS’s response – the company released their first statement about the cyberattack several hours after the reported breach – the attack highlights the importance of having risk management procedures in place to manage the reputational and financial fallout from cyberattacks.

 “Millions of people trust notifications from apps on their phones because they are supposed to come directly from the company,” said Charlotte Wilson, head of enterprise for the UK & Ireland at Check Point. “The fact that an attacker may have been able to hijack that relationship and send a threat directly to customers demonstrates how quickly a cyber incident can move from the server room to the front page, and then straight into the market value of a business.”

At the time of writing, the hackers’ identity was not known, nor the full reason behind the apparent hack. One cybersecurity expert told Sky that attempts at cyber extortion usually happen in private, and it’s possible the hackers have escalated this due to previously being ignored.

The expert view

In the meantime, the experts’ advice for both ASOS and its customers is to keep calm and carry on. Boris Cipot, principal security engineer at Black Duck, said: “We’ve seen this type of scenario before. Earlier this year, for example, the D1R group claimed it had breached Synopsys and obtained sensitive customer information, but Synopsys said its investigation found no evidence that its systems or customer technical data had been accessed without authorisation.

“That’s why, for ASOS and everyone involved, the strongest approach is to keep calm, contain what you can, and investigate. Treat the attackers’ claims seriously, but don’t treat them as facts. Follow the evidence, not the attackers’ narrative.

He added: “For customers, it’s much the same: don’t panic, don’t click the Telegram link, and be particularly careful with emails, texts, or other messages that appear to come from ASOS.”

Stay informed

Our editor carefully curates two newsletters a week filled with up-to-date news, analysis and research. Click here to subscribe to the FREE newsletter sent straight to your inbox. Why not follow us on LinkedIn to receive the latest updates on our research and analysis?

Read More

Subscribe to our email community

Created with Sketch.
Receive the latest news
Created with Sketch.
Be the first to hear about our research
Created with Sketch.
Get VIP access to our events