The ASOS cyber incident began with a push notification. On the morning of 6 October 2026, around 10am, customers of the fashion retailer saw an alert titled “ASOS hacked”. It read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

That is an odd way to deliver a ransom demand, because it was aimed at ASOS staff, but it landed on the phones of customers instead.
Table of Contents
What ASOS has confirmed about the cyber incident
ASOS has been brief. In a statement reported by Malwarebytes, the company said it is “investigating unauthorised activity involving third-party platforms that we use to communicate with customers”. It added that it restricted access to those notification platforms straight away.
The company also said that basic personal information, including names and contact details, may have been accessed. It does not believe payment-card information or account passwords were affected. The UK’s National Cyber Security Centre published its own notice the same day and told customers to assume they are affected, whether or not they received the message.
ASOS says it has around 17 million customers a year across more than 150 countries, so even a small slice of that is a large pool of people to scam.
What is still a claim
A group calling itself Xuanye says it carried out the attack. Malwarebytes reports that the group posted on Telegram that payment information is untouched and the app is safe to use. Nobody has verified either statement, and neither has ASOS confirmed that a Snowflake instance was compromised.
So the facts of the ASOS cyber incident split cleanly. We know a notification went out that ASOS did not authorise. We know ASOS blames a third-party communications platform. Everything else, including the size of any data theft, is unproven.
Malwarebytes also reports that ASOS uses Braze for push notifications and a personalisation tool that runs on Snowflake. That suggests the weak point may sit in the marketing stack rather than the shop itself. ASOS has not said which platform was abused, so treat that as informed context, not a finding.
Why the ASOS cyber incident points at the marketing stack
Most businesses guard the checkout and the customer database, but few give the same attention to the tools that talk to customers: email platforms, push services, SMS gateways and analytics tools. Because those tools hold contact lists, they can send messages that carry the brand’s full authority.
If an attacker reaches one of them, they get data and a trusted voice. A push alert from a retailer’s own app is far more convincing than a spoofed email. That is why this case is worth studying, even if the data loss turns out to be modest.
It also shows how supply chain risk works in practice. Your security can be solid and a supplier’s weak access control still lets someone speak as you. Our guide to software supply chain attacks covers the wider pattern.
What UK businesses should check this week
You do not need to run a global retailer to learn from this. A short review of your own customer messaging tools will tell you a lot.
- List every third-party platform that can send messages to customers, and who holds admin access to each.
- Enforce multi-factor authentication on every one of those accounts, and rotate API keys that have not changed in a year.
- Limit what each tool can see. A push service rarely needs full customer records.
- Set approval steps or alerts for bulk sends, so an unusual campaign gets noticed before it goes live.
- Agree who speaks to customers if a rogue message goes out, and how fast.
A security testing engagement that includes your third-party integrations will show whether a stolen API key or a weak admin login could be turned into a message to your whole customer base.
Advice for ASOS customers
The NCSC guidance is plain. Assume your details may be exposed, and expect scams that use them. Do not click links in unexpected messages, even ones that look like they come from ASOS. Use a strong, unique password and turn on two-step verification or passkeys where offered. Check your account for odd activity, and report fraud through Report Fraud.
After a breach, attackers often send convincing phishing within days, using real names and a plausible story. Reuse of an old password is the other risk. If you used your ASOS password elsewhere, change it there too, which is the same logic behind our piece on credential stuffing.
What to watch next
ASOS has not said how many people are affected or which platform was abused. With the ASOS cyber incident still under investigation, expect further updates, and possibly a filing with the Information Commissioner’s Office if personal data was taken. Until then, the safest reading is the cautious one, because some contact details may be out, payment data probably is not, and the ransom claim is unproven.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.