ASOS Data Breach and “ASOS HACKED” App Notification: What Was Exposed and What to Do

ASOS confirmed that hackers accessed third-party platforms it uses to contact customers after a rogue “ASOS HACKED” push alert went out through its app. Here’s what data may be exposed and how to protect yourself.

By Oscar Leiva

3–5 minutes
Illustration of a phone with a suspicious push notification surrounded by shopping bags and an open padlock, representing an online fashion retailer data breach

Last updated: October 10, 2026

The quick answer

Online fashion retailer ASOS has confirmed that attackers accessed third-party platforms it uses to contact customers, after a rogue “ASOS HACKED” push notification appeared in its app on October 6. ASOS says names and contact details may have been exposed but doesn’t believe passwords or payment-card details were affected; the main risk now is convincing phishing messages that use your real name and contact information.

What happened

On the morning of Tuesday, October 6, 2026, ASOS app users began receiving an unauthorized push notification headlined “ASOS HACKED.” The message was addressed to the company’s data protection officer and IT team, claimed the attackers had fully compromised ASOS’s data on Snowflake, a cloud data platform, and pointed readers to a Telegram channel. A group calling itself Xuanye was behind the message.

ASOS then confirmed that it was investigating unauthorized activity involving third-party platforms used to communicate with customers. In a statement reported by BleepingComputer and Help Net Security, the company said basic personal information, including names and contact details, may have been accessed. It said it had restricted access to the affected platforms and was working with outside specialists and relevant authorities. TechCrunch reported on October 8 that ASOS also disclosed the incident in a London Stock Exchange filing.

Some details remain unconfirmed. ASOS hasn’t said how many customers are affected or confirmed the attackers’ claim about Snowflake. Snowflake told TechCrunch its own systems were not breached. TechCrunch also cited BBC News reporting that the stolen data may include home addresses, phone numbers, email addresses and notes such as customers’ search queries on the site.

What changes for you

If you have an ASOS account, assume your name, email address and possibly phone number and address could be in criminals’ hands. On its own, that isn’t enough to log in to your account or charge your card. But it is exactly what scammers need to write believable emails and texts, such as fake refund offers, “delivery problem” alerts or messages claiming to be from ASOS about the breach itself.

ASOS told customers to ignore the rogue notification and not to click or engage with the external link it contained.

Steps to protect yourself

  1. Don’t follow the notification’s link. If you joined the Telegram channel out of curiosity, leave it and don’t download anything shared there.
  2. Treat ASOS-branded messages with suspicion. Don’t click links in unexpected emails or texts about refunds, vouchers, delivery issues or the breach. Open the ASOS app or type the website address yourself instead.
  3. Never share codes or card details on request. ASOS isn’t going to ask you for a one-time passcode, your password or your full card number by phone, text or email.
  4. Change reused passwords. ASOS doesn’t believe passwords were affected, but if you used your ASOS password anywhere else, changing it is a sensible precaution. A password manager makes unique passwords easy.
  5. Check your account and statements. Review recent orders and saved addresses in your ASOS account, and watch your bank statements for anything unfamiliar.
  6. Be ready for scam calls. If your phone number was on file, be cautious with calls claiming to be from ASOS, your bank or delivery companies. Hang up and call back on an official number.

We covered similar steps after the Oracle Health (Cerner) data breach, and our guide to spotting shopping scams explains the common tricks used in fake retail messages.

Who it affects and who it doesn’t

SituationWhat it means
You have an ASOS accountYour name and contact details may be exposed. Follow the steps above.
You received the “ASOS HACKED” notificationSeeing it doesn’t mean your phone was hacked. It came through ASOS’s notification system. Just don’t follow its link.
You saved a card with ASOSASOS doesn’t believe payment-card data was affected, but keep an eye on statements.
You’ve never had an ASOS accountThis breach doesn’t involve you, though breach-themed scams may still reach you.

Security news is busy today: we also covered expiring Windows Update certificates and a new iPhone spyware variant.

FAQ

Was my ASOS password stolen?

ASOS says it doesn’t believe account passwords were affected. Changing a password you reused on other sites is still a good precaution.

Should I delete the ASOS app?

You don’t need to. The rogue alert came through a notification platform, not through malware on your phone. If you prefer, you can turn off ASOS notifications in your phone’s settings.

How many people are affected?

ASOS hasn’t said. The company has millions of active customers, but not all of them may be affected.

Sources

About the author

Oscar Leiva

Oscar edits Knowloft’s guides from San Salvador, El Salvador, as part of Edén Studio, a creative and software studio. Each guide is built from official data and current local prices, cites its sources and is updated when costs or rules change. Read our editorial standards.

Leave a Reply

More guides

Discover more from Knowloft

Subscribe now to keep reading and get access to the full archive.

Continue reading