ASOS: an unconfirmed hack claim, and what came before it
Developing story on the ASOS data breach claim, written on 6 October 2026. Details may change.
On Tuesday morning, ASOS customers got a push notification that had nothing to do with a sale. By lunchtime the company’s shares were falling. As of writing, ASOS has not confirmed that anything happened. Here is what is known about the ASOS data breach claim, what isn’t, and what ASOS’s earlier incidents add.
ASOS data breach claim: what happened today (6 October 2026)
- The trigger: ASOS app users received a push notification that looked genuine. It claimed the company had been hacked through a Snowflake compromise. It was addressed to ASOS’s data protection officer and IT department and threatened a leak unless the company engaged with the senders.
- Reach and format: Customers in the UK, US, Germany and Australia reportedly received the alert, headed “ASOS HACKED”. It included a Telegram link, apparently to force direct contact or negotiation.
- ASOS’s position: A spokesperson said ASOS was aware of the reports but did not confirm or comment further. The support chatbot reportedly told customers the company was aware and investigating. No samples of customer data or proof of system access had surfaced publicly at the time of writing.
- Market reaction: Shares fell more than 11% on Tuesday, having risen over 60% so far this year. Another report put the fall at 10.2%, to 450.9p.
- Expert reading:
- ESET’s Jake Moore said the push notification suggests access to at least some connected ASOS systems, but doesn’t prove the full claims about the scale of the breach.
- Huntress’s Dray Agha called a ransom demand sent directly to consumer devices an aggressive extortion tactic.
- Regulatory clock: Under UK data protection law, a confirmed breach would require ASOS to notify the regulator within three days.
Earlier ASOS events and possible links
1. The July/August 2026 US account takeover
- ASOS US Sales LLC detected unusual account activity on 28 July and concluded by 29 July that an unauthorised party may have used login credentials obtained outside ASOS.
- Exposed data may have included names, emails, addresses, phone numbers, dates of birth and linked social media details. Redacted card details (cardholder name, last four digits, expiry) may also have been affected.
- ASOS forced password resets on 29 July. The public notification was dated 21 August, over three weeks after detection.
- A law firm investigation put the number affected at about 138,828. Other trackers list far lower figures, with 9,412 Texas residents and 80 Vermont residents in the attorney general filings.
- The numbers don’t reconcile. Some trackers also say full card numbers were exposed, while ASOS’s own letter describes only redacted card data. ASOS’s own notice is the document to rely on.
2. The 2024 Snowflake extortion campaign
- Mandiant attributed that campaign to a group it called UNC5537, with around 165 organisations affected, including AT&T, Ticketmaster, Santander and Neiman Marcus.
- The attacks relied on stolen customer credentials from earlier infostealer malware infections. Mitiga researchers said the group mainly exploited environments without two-factor authentication.
- The suspected ringleader bragged on Telegram and was arrested in Canada in 2024. AT&T reportedly paid $370,000 to have its stolen data deleted.
Is there a link to the earlier ASOS data breach?
- Proven: Nothing found ties today’s claim to the July/August incident or to the 2024 campaign. Any such link is unproven.
- Thematic parallel: Credentials stolen elsewhere drove both the ASOS account takeover and the 2024 Snowflake thefts. If today’s claim holds up, the same weakness (credential hygiene, missing MFA) could be central again. That is a hypothesis, not a finding.
- What can’t be said yet: Who is behind the claim, whether any data was taken, and how the attackers reached the push system are all unknown.
What the ASOS data breach claim means
- Claim versus confirmation: The market moved about 10% on an unverified message. Reputational damage now arrives before the facts do.
- Extortion by push notification: Reaching customers directly through the company’s own app is a new pressure tactic. It also raises the question of how the attackers got access to the push system.
- Two incidents, one theme: Credential-driven access in August, and a claimed cloud data warehouse compromise today. Both point to identity and access controls.
- Disclosure timing: The three-week gap in August sits against the three-day UK regulatory window.
- Practical takeaways:
- Enforce MFA on cloud data platforms.
- Monitor for credential reuse.
- Have a communications plan ready for extortion that goes public.
Sources: Reuters, Infosecurity Magazine, Cybernews, Tech Insider, Investing.com, CyberInsider, eSecurity Planet, GBHackers, ASOS US Sales LLC notice (California AG), The Hacker News, Dark Reading, Help Net Security.





