HomeSecurityASOS hacked: message from hackers to users of the application, what...

ASOS hacked: message from hackers to app users, what to do now

Thousands of ASOS customers opened their phones on October 6, 2026, to find a notification that the company itself had not sent. Entitled “ASOS HACKED,” the message appeared on the official app of the well-known British clothing store, which also has customers in Greece. The senders claimed that they had breached the company’s systems and threatened to leak data.

ASOS confirmed that the alert was “unauthorised” and that it was investigating suspicious activity on external platforms it uses to communicate with its customers. Its initial assessment is that key personal information, such as names and contact details, may have been exposed. The company does not believe that payment card details or passwords were affected.

ASOS customers received a notification from a hacker on their mobile phone

What did the message ASOS customers receive say?

The alert appeared around 10am UK time and was addressed, oddly enough, not to users but to the company itself. In Greek, it read: “Dear ASOS Data Protection Officer and IT Team, we have completely breached the Snowflake environment. Contact us or we will leak it.” Snowflake is a cloud service where many large companies store and analyse data. The message contained a link to a Telegram channel.

Users in the UK, Ireland, France, Sweden and Australia reported receiving the notification, according to the BBC. It is not known how many users received it in total, nor whether it also appeared on mobile users in Greece. ASOS shares fell more than 10% on the London Stock Exchange on the same day.

Who are the hackers and what applies to Snowflake?

The Telegram channel is owned by a group calling itself Xuanye Group. As Bloomberg notes via the Insurance Journal, the group has no prior history of cyberattacks and appears to have created the channel specifically to make its case against ASOS. It later said payment details were not affected and that customer data would not be released for some time, but provided no evidence or proof, The Record.

Snowflake told the BBC that its investigation is ongoing, but so far it has not found any breach of its platform. The hackers' claim of full access to data therefore remains unconfirmed. The only thing that is certain is that someone gained access to the system that sends notifications to users of the app. ASOS said it immediately restricted access to it and that it is working with external experts and the relevant authorities.

See also: Was your information leaked? How to check after the new massive ShinyHunters leak

Parcels from online clothing stores

What to do now, if you are an ASOS customer

First and foremost: do not click on the link in the notification and do not contact the Telegram channel. ASOS itself, in an email to its customers, asked to ignore the message. Receiving the notification does not mean that your phone has been hacked. The message was sent through the application's notification system and not by a program on your device. For updates, visit the official ASOS website directly, typing the address yourself.

Although the company does not believe that passwords were affected, cybersecurity experts who spoke to the BBC recommend the following as a precaution:

  • Change your password on ASOS, especially if you use the same password on other services. In that case, change it there too.
  • Use a different, strong password for each account. A password managermakesthis job much easier.
  • Enable two-step authentication on your important accounts, like email and banking.
  • Monitor your account for orders or changes that you did not make.
Change password and two-step authentication

Beware of fake messages with the subject "ASOS"

The biggest risk for users in the coming days is not the notification itself, but the phishing emails that usually follow such incidents. If names and contact details have indeed been leaked, scammers can use them to send convincing messages that appear to come from ASOS. Such messages may talk about “breach refund”, “account verification”, “compensation voucher” or “problem with your order”.

Suspicious phishing email regarding an order

The SecNews technical team suggests a simple rule: do not trust any email, SMS or phone call that asks for a password, card details or payment, even if it correctly states your name or a real order. Carefully check the sender's address and do not click on links in the message. If you want to check something, open the ASOS app or website yourself. No serious company asks for your password by email or phone.

The case is still ongoing and it is not clear what data, if any, has actually been stolen. As Check Point's Charlotte Wilson noted to the BBC, customers need not feel afraid or threatened, but it is a good idea to take basic protective measures. Until there is further information from the company, being wary of any message with the subject line "ASOS" is the best defense.

See also: AI scams: Fake bank calls and deepfakes – how to avoid falling victim

See also: CPR Register Denmark: Data leak of 8.8 million people

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS