ASOS confirms customer data breach after hackers send rogue app notification
The UK online fashion retailer says names and contact details may have been exposed through third-party platforms. Shares fell about 11% in morning trading, according to FashionUnited.
ASOS confirmed on Tuesday, October 6, 2026, that hackers accessed third-party platforms it uses to contact customers. The attackers had sent an unauthorised “ASOS HACKED” notification through its app on Tuesday, October 6.
The UK online fashion retailer says basic personal information, such as names and contact details, may have been exposed. In the coverage reviewed, ASOS has not said how many of its customers are affected.
What ASOS has confirmed
According to FashionUnited and BleepingComputer, ASOS said the notification was unauthorised and came from activity involving third-party platforms that the retailer uses to communicate with customers. TechCrunch reported that ASOS confirmed the breach in a filing with the London Stock Exchange.
ASOS said it does not believe payment-card information or account passwords were involved. It said it has restricted access to the affected notification platforms. It is investigating with internal and external cybersecurity specialists and with relevant authorities, FashionUnited reported.
The company said its website and app remain operational, with no current disruption to trading. It holds cyber security and business continuity insurance but said it is too early to understand any potential impact on trading, according to FashionUnited.
ASOS is showing customers an in-app notice telling them to disregard the alert and not to click the link in it, BleepingComputer reported.
Share price move
FashionUnited reported that ASOS shares fell about 11% in morning trading, from around 500 pence to 433 pence, before recovering to about 460 pence.
What the attackers claim
The message claimed ASOS’s data held on the Snowflake data platform had been “fully compromised” and ended with a demand that the company engage or face a leak. It pointed to a Telegram channel run by a group calling itself Xuanye Group, FashionUnited and BleepingComputer reported.
ASOS has not confirmed that its Snowflake setup was accessed. Snowflake told TechCrunch that its own systems had not been breached.
BleepingComputer reported that the group first said payment data was not affected, then posted a “final statement” claiming it had stolen customer information. According to BleepingComputer, the group did not say what data was taken or how many people were affected, and it offered no evidence that it had compromised ASOS’s Snowflake environment.
TechCrunch, citing BBC News, reported that the data also includes home addresses, phone numbers, email addresses and profile notes such as website search queries. ASOS has not confirmed those details. TechCrunch also reported, citing BleepingComputer, that the attackers reportedly reached the Snowflake instance by impersonating a trusted contact to obtain login credentials.
Market reaction and scale
FashionUnited reported that ASOS shares fell about 11% in morning trading, from around 500 pence to 433 pence. They later recovered to about 460 pence.
TechCrunch noted that ASOS’s website lists 17 million customers. The company has not said how many of them are affected. FashionUnited described thousands of customers receiving the notification.
FashionUnited placed the incident among other recent cyberattack or data-breach investigations and claims at fashion and retail companies. It named Marks & Spencer, Under Armour, Nike, Adidas and Urban Outfitters.
ASOS has not said how many of its customers are affected.
Open questions and what happens next
Several points are unresolved in the reporting. TechCrunch said it is unclear whether the ASOS Snowflake instance used multi-factor authentication. It also said it is not known how the attackers gained access to the push-notification system, which is often handled by a third-party service.
Customers have been advised to watch for follow-up phishing. FashionUnited said the messages to watch for include those claiming to be from ASOS and asking for password resets, payment information, refunds or order verification.
None of the articles reviewed gives a timetable for completing the investigation. None of the articles reviewed names a regulator or reports a regulatory decision. The scope of the exposed data, and whether the attackers publish any of it, remain unconfirmed in the articles reviewed, the latest dated October 8, 2026.
Photo: MDGovpics · CC BY 2.0 · via Wikimedia Commons



