ASOS confirms data breach after “hacked” app alert reaches shoppers

UK fashion retailer ASOS has confirmed a data breach after a notification claiming hackers had broken into its data was sent to shoppers through its app.

ASOS data breach

ASOS was founded in 2000 and has 16.5 million active customers in more than 100 markets.

According to the company’s update to investors, the unauthorised notification went out to its customers at around 10am on 6 October 2026.

“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities,” reads the company’s statement.

ASOS warned that basic personal information, including names and contact details, may have been accessed. “We do not believe that payment-card information or account passwords, were impacted.”

The company did not disclose how many customers received the notification or how many may have had their information accessed.

“It’s still not known how many people received the pop up message but on Google’s Play store it shows that the Android app for the popular fashion and beauty company has been downloaded more than 10 million times,” noted BBC cyber correspondent Joe Tidy.

“Some of those people might not have app notifications turned on of course but it would make sense that millions of people would have – and so are likely to have got the apparent hacker’s message.”

Attackers claim Snowflake access

A screenshot of the notification, posted by a user on Reddit, shows the message was addressed to the company’s data protection officer (DPO) and IT team. “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” the attackers wrote, followed by a link to a Telegram channel.

The channel belongs to a previously unknown group calling itself Xuanye Group. In posts on the channel, the attackers said payment information was not affected and that the ASOS app was safe to use, according to Reuters. They added that the customer information is held on their server and will be left untouched for a set period of time.

Snowflake, whose cloud platform businesses use to collect, analyse and store data, told the BBC that its investigation is ongoing and that it has so far found “no compromise” of its platform.

“It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access,” said Pieter Arntz, senior malware intelligence researcher at Malwarebytes.

“The mobile app is now the primary interface with consumers for brand loyalty and transactions. If it is compromised, it provides direct access to your customers on the front end and your data on the back end. In the reported ASOS incident, that meant an extortion threat; the same access could make a fake payment request look like routine customer service,” explained Alan Snyder, CEO at NowSecure.

“That’s why mobile app security has to include the accounts and connected services authorized to send messages. Retailers need to know who has that access, what else it allows and how quickly they can revoke it. Customers shouldn’t have to figure out whether their shopping app is speaking for the retailer or an attacker,” added Snyder.

The incident follows cyberattacks on several UK retailers in 2025, including Marks & Spencer, the Co-op and Harrods.

Don't miss