ASOS Data Breach: What Hackers Took via Its App Alert, and What to Do
At about 10am on Tuesday 6 October, people with the ASOS app on their phones got a push alert headed “ASOS HACKED”. It was not really meant for them. “Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” the message read, according to BleepingComputer, and it pointed to a Telegram channel run by a group calling itself Xuanye.
Two days later ASOS confirmed what its customers wanted to know. In an update on 8 October, the online fashion retailer said “an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact,” then used those login details to reach information on third-party platforms, BleepingComputer reported. Names and contact details were taken. Payment cards and account passwords were not, ASOS says.
So the risk for most shoppers is not a drained card. It is the next email, text or call that claims to be from ASOS and knows a little too much about you. Here is what was taken, what ASOS says was not, and what to do, in order.
ASOS data breach: what was taken, and what ASOS says wasn’t
ASOS’s first word came in a 6 October notice to the London Stock Exchange, timed at 3.15pm. It said “basic personal information including name and contact details may have been accessed” and that it did not believe payment-card information or account passwords were affected, as ITV News quoted it. The shares fell as much as 15% in London that day and closed about 10% lower, Computing reported.

The 8 October customer update firmed that up. Beyond names and contact details, ASOS said “some personal information” and “non-personal related information” were accessed, without saying what either covers, according to a summary published by AOL. It said the affected platforms “were immediately locked down” and that it was working with law enforcement and regulators. ASOS shares rose as much as 5.3% on the news that the attack was narrower than feared, Bloomberg reported.
The BBC saw more. Cyber correspondent Joe Tidy reported that the attackers sent a data sample on the evening of 7 October containing names, addresses, phone numbers, email addresses, customer numbers and dates of birth, plus search history on the ASOS site, with entries such as “reclaimed vintage” and “glamorous wide fit” (BBC report, via Yahoo). ASOS has not confirmed that the sample is genuine or how many people it represents. The BBC put the possible scale at “potentially millions”.
How the data left is still disputed. The group first claimed it had cracked ASOS’s Snowflake data store; it later told the BBC it went in through Simon AI, a marketing platform built on Snowflake. Snowflake says its own platform was not breached, per Bloomberg. How the attackers got hold of the app’s push notification system, which is often run by an outside service, is also unexplained, TechCrunch noted.
Who is Xuanye?
Nobody knows much. Group-IB’s Anastasia Tikhonova told Bloomberg the group’s Telegram account had been active since early September under another username, had mainly traded online gaming items and had not previously been linked to any cyberattack. The group has reportedly given ASOS two weeks to make contact and demanded a ransom to delete the data, Malwarebytes reported. ASOS has not said whether it will engage.
What to do now if you shop with ASOS
ASOS says you do not need to change anything on your account and that its website and app are safe to use. That is a reasonable floor. These steps go a little further, in order of what matters most.
- Ignore the alert and its link. In an email to customers ASOS said: “Please disregard the notification and do not click or engage with the external third-party link it contained.” Its help page on the incident says the same.
- Treat any “ASOS” contact as suspect for months, not days. ASOS says: “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.” The danger in this breach is precision. A scammer who knows your address, date of birth and what you searched for can write a far more convincing refund or delivery message than one guessing in the dark. Which? tech editor Lisa Barber made the same point about spear phishing, AOL reported.
- Go to ASOS yourself. If a message about an order, refund or account problem worries you, open the app or type asos.com and use Customer Care from there. The UK National Cyber Security Centre’s data breach guidance gives the same rule: use the organisation’s official website, not contact details in a message.
- Report fakes, and act fast if money moves. Forward suspicious emails to report@phishing.gov.uk and texts to 7726, as GOV.UK advises. If you have lost money or think you have been scammed, call your bank on 159 or the number on the back of your card, as Which? recommends, and report it to Report Fraud at reportfraud.police.uk or 0300 123 2040 (Police Scotland on 101 in Scotland), per the NCSC.
- Tidy your passwords anyway. ASOS says passwords were not accessed. If you reused your ASOS password elsewhere, change it on those sites now; it costs five minutes. The NCSC suggests checking Have I Been Pwned for older breaches and switching to a passkey where offered. Our passkeys guide walks through setting them up.
- Ask ASOS what it holds on you. Under UK data protection law you can make a subject access request, and the Information Commissioner’s Office says organisations usually have one month to respond. It is the cleanest way to find out whether your search history and date of birth sit on the kind of platform that was hit.
- Shopping from Canada? The same scam risk applies. The Office of the Privacy Commissioner of Canada’s breach advice is to keep any notice you receive, watch your accounts and stay alert for scams, because fraudsters may wait before using stolen information. Nothing reported so far suggests government ID numbers were involved; if a future breach does expose your SIN, see our SIN and SSN guide.
What ASOS still hasn’t said
ASOS has not said how many customers are affected, whether the BBC’s sample matches its own findings, or which platform sent the rogue alert. It says its investigation will continue and that it will contact customers directly where needed.
The regulators are now involved. On 6 October the Information Commissioner’s Office said neither ASOS nor Snowflake had contacted it, Computing reported; by 8 October the ICO told Bloomberg that ASOS had notified it and that it was assessing the information. The NCSC said it was in contact with ASOS and had offered support.
The next message in your inbox will not say “ASOS HACKED”. It may mention a wide-fit order.
Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.
Latest from prompt/power
- Uber and Pony.ai Robotaxis Head for London Tests. Here’s What’s ApprovedOct 11
- Surface Laptop Ultra UK Price Is £2,599. Here’s the Real British MarkupOct 11
- AI Safety Hearing: MPs Will Question OpenAI, Anthropic, Google and Meta on 13 OctOct 11
- National Medal of Science Goes to Musk, Brin, Huang and Su. Nvidia Pledged US$1BOct 10
- TikTok Placebo Safety Test: New York Says Teens Got a Fake Feed ResetOct 10
Leave a Reply