ASOS apologises after a hacker‑crafted alert leaked personal details, prompting shoppers to secure passwords and watch for scams.

On Tuesday, 6 October, shoppers using the ASOS mobile app were greeted by a startling pop-up titled “Asos hacked”. The message contained a link to a Telegram account and warned of a compromise of the retailer’s Snowflake data-storage instance.
Within hours, ASOS confirmed that the notification had not been authorised by the company and that hackers had managed to retrieve certain pieces of customer information.
The retailer, which serves roughly 16.5 million users worldwide, swiftly disabled the compromised notification channel, engaged internal and external cyber-security advisers, and alerted the relevant authorities.
While the incident sparked a sharp drop in the company’s share price, the firm reassured the public that its e-commerce platform and ordering systems remained fully operational.
How the unauthorised alert was delivered
Investigators traced the fake message to a third-party communication platform that interfaces with ASOS’s app.
The hackers, identifying themselves as the group “Xuanyewen”, claimed to have accessed the Snowflake instance – a cloud-based data-warehouse service employed by the retailer. Snowflake’s own investigation, however, found no evidence of a breach within its infrastructure, suggesting that the attackers exploited a separate layer built on top of Snowflake, reportedly a tool called Simon AI. The notification’s Telegram link was designed to lure recipients into a conversation with the perpetrators, a classic phishing technique.
What personal data may have been exposed
ASOS disclosed that the compromised files included names, email addresses, phone numbers, postal addresses and customer identification numbers. In addition, the breach revealed users’ recent search terms – examples such as “reclaimed vintage”, “glamorous wide fit” and “Asos petite” – providing a detailed picture of individual shopping interests. Crucially, the retailer stated that it has no evidence of payment-card details or account passwords being accessed, and the National Cyber Security Centre (NCSC) echoed this assessment. Nevertheless, the exposure of detailed profiles creates a fertile ground for targeted phishing and identity-theft attempts.
Steps customers should take immediately
Security experts advise anyone who uses ASOS – even if they did not receive the fraudulent alert – to treat their account as potentially vulnerable. First, avoid clicking any links contained in unexpected messages, especially those directing to messaging apps or unfamiliar domains. Second, change the ASOS password and any other online service that shares the same credentials; a robust password combines letters, numbers, symbols and mixed case. Third, activate two-factor authentication (2FA) wherever the option exists, a measure the NCSC describes as one of the most effective defenses against account takeover. Finally, monitor banking statements and online transactions for any irregular activity, and report suspicious communications to the relevant fraud-prevention bodies.
Broader implications and industry response
The ASOS incident adds to a growing list of UK retailers hit by cyber-criminals over the past two years, including Marks & Spencer, Harrods and Jaguar Land Rover. Analysts note that attackers are increasingly targeting third-party services that sit between consumers and large brands, exploiting the complex supply-chain of modern digital platforms. The breach also highlights the importance of incident response planning and the need for retailers to maintain continuous monitoring of all external integrations. While ASOS’s cyber-security insurance will mitigate some financial fallout, the reputational impact underscores why organisations must prioritise data-privacy safeguards.
Customers seeking updates should visit the official ASOS website or app, where the company promises to communicate further details should new information arise. In the meantime, staying vigilant, reinforcing account security and being skeptical of unsolicited messages remain the best personal defence against the ripple effects of this breach.

