ASOS investigates unauthorised activity after customers receive hack alert

The fashion retailer says personal details of some of its 16.5 million customers may have been accessed, but payment data was not compromised.

By Felo News Desk · Published

ASOS said it is investigating "unauthorised activity" involving a third‑party platform after customers received a mobile‑app notification on Tuesday that claimed the retailer had been hacked.

What happened

On Tuesday, the ASOS app pushed a notification titled “Asos hacked” that directed users to a Telegram account. The message, quoted by the company, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,” followed by a Telegram link.

What the reports add

  • The Independent and the Standard reported that personal information such as names and contact details “may have been accessed”, but ASOS does not believe payment‑card data or passwords were impacted.
  • Both outlets noted that the National Cyber Security Centre (NCSC) offered assistance and that its chief executive, Dr Richard Horne, said the incident highlights how cyber incidents can affect individuals widely.
  • Snowflake, the cloud data‑warehousing firm referenced in the fake message, said it has found no compromise of its platform after launching its own investigation.
  • Shares in ASOS fell by more than 10% on Tuesday following the notification.

What was said

“We are investigating unauthorised activity involving third‑party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities,”

ASOS said in a statement, quoted by both the Independent and the Standard.

Dr Richard Horne, chief executive of the NCSC, said: “The unauthorised notification sent out to Asos customers has brought into the light how cyber incidents do not simply affect big business but can have repercussions for individuals much more widely too. The NCSC has been in contact with Asos today to offer our support as the company investigates what has taken place. Individuals who received the notification should not click on any suspicious links and should stay vigilant to suspicious messages that may seek to take advantage of news of the breach.”

How it came about

ASOS, which serves 16.5 million customers, uses third‑party services such as Snowflake for data processing. The fake notification appears to have exploited that integration, prompting the retailer to launch an investigation. Earlier this month, Felo reported on broader cyber‑security concerns affecting UK firms, highlighting the growing reliance on cloud‑based platforms.

Key facts

  • ASOS sent a mobile‑app notification titled “Asos hacked” that linked to a Telegram account. (independent.co.uk)
  • The message claimed the Snowflake instance was fully compromised. (standard.co.uk)
  • ASOS says personal information such as names and contact details may have been accessed, but payment card data was not impacted. (independent.co.uk)
  • ASOS restricted access to the notification platforms and is working with specialist advisers and authorities. (standard.co.uk)

Sources

Earlier coverage

More from Business

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com