ASOS data breach opinion Header

ASOS Data Breach: Hack Partly Confirmed, What Came Before

ASOS: a partly confirmed hack, and what came before it

Developing story on the ASOS data breach, first written on 6 October 2026 and updated on 7 October 2026. Details may change.

On Tuesday morning, ASOS customers got a push notification that had nothing to do with a sale. By lunchtime the company’s shares were falling. By the afternoon ASOS had confirmed that third-party platforms it uses to communicate with customers were accessed without authorisation. It has not confirmed the wider claim about its data. Here is what is known about the ASOS data breach, what isn’t, and what ASOS’s earlier incidents add.

ASOS data breach: what happened on 6 October 2026

  • The trigger: ASOS app users received a push notification that looked genuine. It claimed the company had been hacked through a Snowflake compromise. It was addressed to ASOS’s data protection officer and IT department and threatened a leak unless the company engaged with the senders.
  • Reach and format: Customers in the UK, US, Germany and Australia reportedly received the alert, headed “ASOS HACKED”. It included a Telegram link, apparently to force direct contact or negotiation.
  • ASOS’s position: At first a spokesperson said ASOS was aware of the reports but did not confirm or comment further. Later that day ASOS confirmed that an “unauthorised customer notification” had been sent and that “third-party platforms used to communicate with customers were accessed without authorization”. It said it took immediate action to restrict access to the notification platforms. An in-app notice told customers to disregard the alert and not to click the link in it.
  • What ASOS says was exposed: Basic personal information, including names and contact details, may have been exposed. ASOS said it does not believe payment-card information or account passwords were affected. It has not said how many customers are involved.
  • What is still unconfirmed: ASOS has not confirmed that its Snowflake environment was compromised. A group calling itself “Xuanye group” claimed responsibility. It has not published evidence, and its identity and origin are unverified.
  • Market reaction: Shares fell more than 11% on Tuesday, having risen over 60% so far this year. Another report put the fall at 10.2%, to 450.9p.
  • Expert reading:
    • ESET’s Jake Moore said the push notification suggests access to at least some connected ASOS systems, but doesn’t prove the full claims about the scale of the breach.
    • Huntress’s Dray Agha called a ransom demand sent directly to consumer devices an aggressive extortion tactic.
    • Researchers warned that follow-up phishing campaigns are likely, exploiting the publicity.
  • Regulatory clock: Under UK data protection law, a notifiable breach must be reported to the regulator within three days of the organisation becoming aware of it. ASOS has now said customer contact details may have been exposed. No regulator statement had been reported at the time of writing.

Earlier ASOS events and possible links

1. The July/August 2026 US account takeover

  • ASOS US Sales LLC detected unusual account activity on 28 July and concluded by 29 July that an unauthorised party may have used login credentials obtained outside ASOS.
  • Exposed data may have included names, emails, addresses, phone numbers, dates of birth and linked social media details. Redacted card details (cardholder name, last four digits, expiry) may also have been affected.
  • ASOS forced password resets on 29 July. The public notification was dated 21 August, over three weeks after detection.
  • A law firm investigation put the number affected at about 138,828. Other trackers list far lower figures, with 9,412 Texas residents and 80 Vermont residents in the attorney general filings.
  • The numbers don’t reconcile. Some trackers also say full card numbers were exposed, while ASOS’s own letter describes only redacted card data. ASOS’s own notice is the document to rely on.

2. The 2024 Snowflake extortion campaign

  • Mandiant attributed that campaign to a group it called UNC5537, with around 165 organisations affected, including AT&T, Ticketmaster, Santander and Neiman Marcus.
  • The attacks relied on stolen customer credentials from earlier infostealer malware infections. Mitiga researchers said the group mainly exploited environments without two-factor authentication.
  • The suspected ringleader bragged on Telegram and was arrested in Canada in 2024. AT&T reportedly paid $370,000 to have its stolen data deleted.

Is there a link to the earlier ASOS data breach?

  • Proven: Nothing found ties the October incident to the July/August incident or to the 2024 campaign. Any such link is unproven.
  • Thematic parallel: Credentials stolen elsewhere drove both the ASOS account takeover and the 2024 Snowflake thefts. If the Snowflake claim holds up, the same weakness (credential hygiene, missing MFA) could be central again. That is a hypothesis, not a finding.
  • What can’t be said yet: How the attackers got into the notification platforms, whether the Snowflake claim is true, how many customers are affected and who is behind it are all unknown.

What the ASOS data breach means

  1. Claim versus confirmation: The market moved about 10% on an unverified message. ASOS’s later confirmation was narrower than the claim: the alert was real and customer contact details may be exposed, but the Snowflake claim is unconfirmed. Reputational damage arrived before the facts did.
  2. Extortion by push notification: Reaching customers directly through the company’s own app is a new pressure tactic. ASOS has confirmed that the platforms it uses to communicate with customers were accessed, which explains how the alert was sent. It does not explain how the attackers got in.
  3. Two incidents, one theme: Credential-driven access in August, and a claimed cloud data warehouse compromise on 6 October. Both point to identity and access controls, though the cause of the October incident is unconfirmed.
  4. Disclosure timing: In August the public notification came over three weeks after detection. In October ASOS confirmed within hours. The three-day UK regulatory window sits against both.
  5. Practical takeaways:
    • Enforce MFA on cloud data platforms.
    • Monitor for credential reuse.
    • Treat third-party customer-communication platforms as high-risk access, not just the core database.
    • Warn customers early about follow-up phishing.
    • Have a communications plan ready for extortion that goes public.

Opinion: the ASOS data breach was never in doubt

This section is our opinion, not a finding. ASOS has not said how the attackers got in.

Why “did a breach happen?” was the wrong question

  • The alert arrived through ASOS’s own app, sent by someone who was not ASOS. That is unauthorised access to a live system, and every customer who received it was the proof.
  • What was unverified was the scale and the Snowflake claim. Scepticism about those was right. Doubt that anything had happened was never a credible position.
  • The early framing of this story led with “unconfirmed”. It hedged the wrong thing. The incident was visible on day one, and only its extent was open.
  • ASOS’s own confirmation, within hours, said just that: its notification platforms were accessed without authorisation.

Does personal data have to be exposed for a breach to occur?

  • In law, for a personal data breach, yes. UK GDPR defines it as a security breach that leads to unauthorised access to, or loss, alteration or disclosure of, personal data. That definition triggers the regulator-notification duty.
  • For a security breach, no. Attackers who get into a system without permission have breached its security, whatever sits behind it.
  • Access can be enough. The definition covers unauthorised access, so data does not have to be copied or leaked. A customer-communications platform usually holds names, contact details and device identifiers, which is why ASOS’s own wording about contact details matters.
  • Integrity counts as well as confidentiality. The ICO treats breaches as confidentiality, integrity or availability failures. A fake message sent through a company’s own channel is an integrity failure even if no record left the building.
  • Serious harm needs no stolen records. Customers received a threatening message from a brand they trust. They were primed for phishing. The shares fell about 10% in a day. Platforms had to be shut down, and an extortion channel was opened to the public.
  • Judge severity by harm, not by proof of a data dump. Record the assessment either way. UK GDPR requires organisations to document every personal data breach, including the ones they decide not to report.

Why ASOS needs to tighten security

  • This is two incidents in about ten weeks: credential stuffing in late July, and platform access on 6 October. The methods differ, but both ask who and what can get in.
  • With the shares up over 60% this year, investors have priced in resilience. One alert took about 10% off in a day.
  • The cause of the October incident is unknown. These are the areas we would expect ASOS to check, not allegations:
    • Strong authentication, such as MFA or passkeys, on every platform that can reach customers, for staff and vendors alike.
    • Approval controls on mass sends: sign-off by a second person, rate limits and alerts on unusual campaigns.
    • Credential-stuffing defences on customer accounts: bot detection, breached-password checks and MFA or passkeys for customers.
    • Tighter third-party access: least privilege, key rotation, regular access reviews and retained logs.
    • Separation between systems, so that a compromised messaging platform cannot reach the data warehouse.
    • Faster, clearer disclosure. The August notice took over three weeks.
  • Our view: confirm quickly, explain how it happened, then show the fix.

Sources: BleepingComputer, TechRadar, Reuters, Infosecurity Magazine, Cybernews, Tech Insider, Investing.com, CyberInsider, eSecurity Planet, GBHackers, ASOS US Sales LLC notice (California AG), The Hacker News, Dark Reading, Help Net Security.

Manage personal data and privacy risks

Scroll to Top

Contact us

If you would like to ask more questions or to arrange training, complete the form below and we will respond shortly.

Prefer to schedule a 15 minute call? Schedule call today >>

See our Privacy Statement for more details.