Asos customers targeted by unauthorized hack notification; here's what to do

criminals know people will be searching for information online
Security experts warn that the real danger may come from follow-up scams exploiting the confusion around the breach.
Mark

So what actually happened here? Did Asos get hacked or not?

Mimi

That's the thing—it's genuinely unclear. Someone sent a message claiming they'd compromised Asos's data systems, but Snowflake, the company mentioned in the threat, says its platform wasn't breached. So either the attackers got in through a different route, or they were bluffing to extort the company.

Luke

Right, and we should be clear: Asos hasn't confirmed what was actually accessed. They're saying basic personal info *may* have been exposed, but they don't know for certain yet. It's been less than 24 hours.

Mark

What's the real risk for customers right now?

Mimi

The immediate risk is that people will panic and fall for follow-up scams. Criminals know there's confusion, and they'll send fake emails or texts pretending to be Asos, asking people to click links or reset passwords.

Luke

That's actually the bigger threat than the original breach, according to the security experts quoted. The breach itself is still being investigated.

Mark

So what should someone actually do if they got the notification?

Mimi

Don't click the link. Change your password. Turn on two-step verification for important accounts. Watch your transactions. And be very skeptical of any follow-up messages claiming to be from Asos.

Luke

Those are all solid steps. The two-step verification part is worth emphasizing—the National Cyber Security Centre calls it one of the most effective defenses.

Mark

How many people are we talking about?

Mimi

Asos hasn't said. The notification went out to customers across the UK on Tuesday morning, but the company hasn't disclosed how many people received it or how many might be affected.

Luke

That's a significant gap. We know it happened, we know some data may have been accessed, but the scale is still unknown. Asos said it'll provide more information as the investigation continues.

  • Thousands of Asos customers received alarming in-app pop-ups from apparent hackers threatening to leak data unless the company engaged with them — a brazen act of public extortion delivered through the retailer's own infrastructure.
  • Within hours, Asos cut off the attackers' access and began working with advisers and law enforcement, but fundamental questions — who sent the message, how many were affected, and the true scale of exposure — remained unanswered by nightfall.
  • Snowflake, the cloud platform named in the extortion message, told the BBC its own systems showed no signs of compromise, leaving open the unsettling possibility that the attackers either bluffed or found another way in.
  • Security experts warn that the real danger may now come in the breach's aftermath, as scammers exploit public fear with phishing emails, fake refund calls, and fraudulent password-reset requests impersonating Asos.
  • Customers are urged to change passwords immediately, enable two-step verification on critical accounts, avoid clicking any links from the notification, and monitor financial transactions closely for suspicious activity.

In the early hours of a Tuesday morning, thousands of Asos shoppers found themselves unwilling participants in a digital extortion drama, receiving push notifications through the retailer's own app from actors claiming to have breached its cloud data systems. Asos moved swiftly to restrict access and launch an investigation, confirming that basic personal details may have been exposed while offering measured reassurance that payment and password data appeared unaffected. The episode is a reminder that in the modern marketplace, the boundary between customer and target is thinner than most realize — and that the chaos following a breach can be as dangerous as the breach itself.

On a Tuesday morning, thousands of Asos customers received a deeply unsettling push notification through the retailer's own app. The message was blunt: hackers claimed to have fully compromised Asos's Snowflake cloud instance and demanded the company engage with them — or face a data leak. A link to a Telegram account was embedded in the notification, which security experts quickly flagged as something customers should not touch.

By evening, Asos had restricted the attackers' access and launched an investigation alongside advisers and law enforcement. The company confirmed that basic personal information — names and contact details — may have been exposed, but offered some relief: payment card data and passwords appeared to have remained safe. Snowflake, for its part, told the BBC that its own systems showed no evidence of compromise, raising questions about whether the attackers were bluffing or had reached Asos's data through a different route.

Nevertheless, uncertainty dominated the hours that followed. Cybersecurity experts noted that an enormous amount remained unknown — and pointed to a danger that often follows breaches: criminals exploiting the fear and confusion of affected customers. Phishing emails, fake refund calls, and fraudulent messages impersonating Asos were flagged as likely to follow. Consumer rights organization Which? advised anyone receiving a call claiming to be from Asos to hang up and contact the company directly through official channels.

For customers, the guidance is clear: do not click the link in the notification, change your Asos password and any others you've reused, enable two-step verification on critical accounts, and watch your financial transactions carefully. As of Tuesday night, Asos's website and app were operating normally, and the company promised further updates as its investigation progressed. For reliable information, customers are advised to visit Asos's official website directly — and treat any unsolicited message with suspicion.

On Tuesday morning, thousands of Asos customers woke to an unsettling message on their phones. The pop-up, delivered through the retailer's app, contained a stark demand: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The message appeared to come from hackers attempting to extort the company, and it arrived with a link to a Telegram account—a detail that would soon become central to the advice Asos and security experts began issuing within hours.

By Tuesday evening, Asos had moved quickly to contain the breach. The company restricted the attackers' access, launched an investigation, and began coordinating with advisers and law enforcement. In a statement to customers, Asos acknowledged that basic personal information—names and contact details—may have been accessed. But the company offered some reassurance: payment card data and account passwords appeared to have remained untouched. Snowflake, the cloud data storage platform mentioned in the extortion message, separately told the BBC that its own investigations found no evidence that its systems had been compromised, suggesting the attackers may have been bluffing or had accessed Asos's data through another route.

The uncertainty, however, remains substantial. Less than 24 hours after the notifications appeared, fundamental questions remained unanswered. No one yet knew who sent the message, how many customers received it, or the true scope of any data exposure. Charlotte Wilson, head of enterprise at the cybersecurity firm Check Point, observed that "an awful lot" remains unknown—and she flagged what may be the most immediate danger: criminals will exploit the confusion and fear now rippling through Asos's customer base.

For those who received the notification, the guidance is straightforward but requires discipline. Do not click the link embedded in the message. Change your Asos password immediately, and if you've used the same password elsewhere, update those accounts too. Security experts recommend mixing numbers, symbols, and both uppercase and lowercase letters, and avoiding password reuse across sites. Enable two-step verification on critical accounts—banking, email, and any service tied to payment methods. The National Cyber Security Centre describes this as one of the most effective defenses against criminal access. Monitor your financial transactions closely for any suspicious activity.

But the real threat may come sideways. Wilson warns customers to be "extremely suspicious" of follow-up emails, texts, or calls claiming to be from Asos and offering refunds or requesting password resets. Kat Cereda, a spokesperson for Which?, the consumer rights organization, advises anyone receiving a call from someone claiming to represent Asos to hang up and then contact the company directly through official channels—never through a number or link provided by the caller. Scammers routinely ride waves of legitimate breaches, using public panic as cover for their own phishing attempts.

As of Tuesday night, Asos reported that its website and app were functioning normally and that customers could continue shopping without disruption. The company promised further updates as soon as its investigation yielded confirmed information. For now, the retailer's priority, it said, is protecting its customers—though the full scope of what needs protecting remains unclear. Anyone seeking reliable updates should visit Asos's official website directly, bypassing any links or messages that arrive unsolicited.

The biggest immediate risk may be what happens next—criminals know people will be searching for information online and will attempt to exploit that confusion.
— Charlotte Wilson, head of enterprise at Check Point
Two-step verification is one of the most effective ways to protect your online accounts from cyber criminals.
— National Cyber Security Centre
Envie de l'histoire complète ? Lire l'original sur BBC News ↗
Nous contacter FAQ