Last updated: October 10, 2026
The quick answer
Online fashion retailer ASOS has confirmed that attackers accessed third-party platforms it uses to contact customers, after a rogue “ASOS HACKED” push notification appeared in its app on October 6. ASOS says names and contact details may have been exposed but doesn’t believe passwords or payment-card details were affected; the main risk now is convincing phishing messages that use your real name and contact information.
What happened
On the morning of Tuesday, October 6, 2026, ASOS app users began receiving an unauthorized push notification headlined “ASOS HACKED.” The message was addressed to the company’s data protection officer and IT team, claimed the attackers had fully compromised ASOS’s data on Snowflake, a cloud data platform, and pointed readers to a Telegram channel. A group calling itself Xuanye was behind the message.
ASOS then confirmed that it was investigating unauthorized activity involving third-party platforms used to communicate with customers. In a statement reported by BleepingComputer and Help Net Security, the company said basic personal information, including names and contact details, may have been accessed. It said it had restricted access to the affected platforms and was working with outside specialists and relevant authorities. TechCrunch reported on October 8 that ASOS also disclosed the incident in a London Stock Exchange filing.
Some details remain unconfirmed. ASOS hasn’t said how many customers are affected or confirmed the attackers’ claim about Snowflake. Snowflake told TechCrunch its own systems were not breached. TechCrunch also cited BBC News reporting that the stolen data may include home addresses, phone numbers, email addresses and notes such as customers’ search queries on the site.
What changes for you
If you have an ASOS account, assume your name, email address and possibly phone number and address could be in criminals’ hands. On its own, that isn’t enough to log in to your account or charge your card. But it is exactly what scammers need to write believable emails and texts, such as fake refund offers, “delivery problem” alerts or messages claiming to be from ASOS about the breach itself.
ASOS told customers to ignore the rogue notification and not to click or engage with the external link it contained.
Steps to protect yourself
- Don’t follow the notification’s link. If you joined the Telegram channel out of curiosity, leave it and don’t download anything shared there.
- Treat ASOS-branded messages with suspicion. Don’t click links in unexpected emails or texts about refunds, vouchers, delivery issues or the breach. Open the ASOS app or type the website address yourself instead.
- Never share codes or card details on request. ASOS isn’t going to ask you for a one-time passcode, your password or your full card number by phone, text or email.
- Change reused passwords. ASOS doesn’t believe passwords were affected, but if you used your ASOS password anywhere else, changing it is a sensible precaution. A password manager makes unique passwords easy.
- Check your account and statements. Review recent orders and saved addresses in your ASOS account, and watch your bank statements for anything unfamiliar.
- Be ready for scam calls. If your phone number was on file, be cautious with calls claiming to be from ASOS, your bank or delivery companies. Hang up and call back on an official number.
We covered similar steps after the Oracle Health (Cerner) data breach, and our guide to spotting shopping scams explains the common tricks used in fake retail messages.
Who it affects and who it doesn’t
| Situation | What it means |
|---|---|
| You have an ASOS account | Your name and contact details may be exposed. Follow the steps above. |
| You received the “ASOS HACKED” notification | Seeing it doesn’t mean your phone was hacked. It came through ASOS’s notification system. Just don’t follow its link. |
| You saved a card with ASOS | ASOS doesn’t believe payment-card data was affected, but keep an eye on statements. |
| You’ve never had an ASOS account | This breach doesn’t involve you, though breach-themed scams may still reach you. |
Security news is busy today: we also covered expiring Windows Update certificates and a new iPhone spyware variant.
FAQ
Was my ASOS password stolen?
ASOS says it doesn’t believe account passwords were affected. Changing a password you reused on other sites is still a good precaution.
Should I delete the ASOS app?
You don’t need to. The rogue alert came through a notification platform, not through malware on your phone. If you prefer, you can turn off ASOS notifications in your phone’s settings.
How many people are affected?
ASOS hasn’t said. The company has millions of active customers, but not all of them may be affected.



Leave a Reply