UK online fashion retailer ASOS has confirmed that customers' personal details were taken in a cyber attack, after a message from the attackers was sent to shoppers through the ASOS app. The company says names and contact details were exposed but that payment card details and account passwords were not.
The data involved is the kind scammers use to make messages look genuine: a name, a home address, a phone number and an email address, and in some cases notes about what a customer has searched for on the site.
What happened
In a statement to the London Stock Exchange on 6 October 2026, ASOS said that "at around 10am today, an unauthorised customer notification was sent to ASOS customers." It said it was "investigating unauthorised activity involving third-party platforms that we use to communicate with customers" and added: "We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities."
The notification itself was addressed to the company, not to shoppers. According to Help Net Security, which reported a screenshot posted by a user, it read: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." It linked to a Telegram channel run by a previously unknown group calling itself Xuanye Group.
Snowflake, the cloud data company named in the message, told the BBC that its investigation was ongoing and that it had so far found "no compromise" of its platform, Help Net Security reported. ASOS's stock exchange statement does not name Snowflake.
How the attackers got in
In a later security notification shared with BleepingComputer and reported on 8 October, ASOS said: "We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials." It added: "Those credentials were then used to access information on certain third-party platforms used by ASOS."
That describes a social engineering attack on a member of staff rather than a flaw in the ASOS website. ASOS says its website and app were safe to use throughout and that it has taken steps to add further security measures.
What data was exposed
ASOS's first statement said "basic personal information including name and contact details may have been accessed." According to BleepingComputer, the later update sent to customers lists full names, contact details and certain non-personal account-related information. TechCrunch, citing BBC News, reports that the stolen data includes home addresses, phone numbers and email addresses, as well as notes relating to customer profiles such as website search queries.
ASOS says payment card information and account passwords were not accessed.
Who is affected
ASOS has not said how many customers are affected. BleepingComputer said it had asked for a figure and had not received one. Help Net Security reports that ASOS has 16.5 million active customers in more than 100 markets, and TechCrunch says the company has 17 million customers according to its website. Neither number is a count of affected people. ASOS has also not said how many people received the app notification.
What ASOS customers should do
ASOS's advice is: "There is no action you need to take on your account. However, please remain cautious of unexpected messages or calls claiming to be from ASOS." It adds: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
Because ASOS says passwords were not taken, a password change is not required, though it does no harm, and it matters more if you used the same password anywhere else. The bigger risk is phishing. Someone who knows your name, address, phone number and shopping interests can write an email or text that looks very like a real order update, refund notice or delivery problem.
- Treat any unexpected message about an ASOS order, refund or account problem with suspicion, especially if it asks you to click a link, call a number or confirm card details. Open the app or type the website address yourself instead.
- Be wary of follow-up messages that mention the breach itself, such as offers of compensation or requests to verify your account.
- In the UK, forward suspicious emails to the National Cyber Security Centre at report@phishing.gov.uk. The NCSC asks people to send emails "that feel suspicious, even if you're not certain they're a scam".
- Turn on two-step verification for your email account, since email is what resets most other accounts.
- If you already use an identity protection or monitoring service, make sure your current address, phone number and email are on its watch list. The data ASOS describes does not include card numbers, passwords or identity documents, so the main risk it points to is targeted scams.
What is still unknown
ASOS has not said how many customers' records were taken, which third-party platforms were accessed, when the attackers first got in, or how they were able to send a push notification through the app. TechCrunch notes it is unclear whether the account involved was protected by multi-factor authentication. It is not known whether the group will publish the data. ASOS says its investigation continues and that it will share updates if important findings emerge. In its stock exchange statement it said it was too early to quantify any impact on trading.