Asos appears to have been hacked after customers received an ‘unusually brazen’ message threatening to leak their data.Â
The phone alert was sent on the online fast-fashion retailer’s app today, titled ‘ASOS hacked’, and read: ‘Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it: t.me/xuanyewengateway.’Â
DPO refers to the data protection officer in charge of safeguarding customers’ information. Snowflake is a cloud platform that is used to store, process and analyse data.
It also collects customers’ behavioural, transactional and demographic data.Â
The Daily Mail has contacted Asos for comment.Â
Asos says it has 17 million customers in 150 countries. Its website and app appear to be working still despite the apparent breach.Â
The firm’s shares plummeted by 11 per cent after reports of the hacking emerged.Â
Panicked customers have been reacting online to the ‘crazy notification’, and some said they have ‘never deleted my payment methods so quick’.
Asos appears to have been hacked after customers received a message threatening to leak their data
Asos says it has 17 million customers in 150 countries. Its website and app appear to be working still despite the apparent breach
Marijus Briedis, chief technology officer at NordVPN, said it was ‘an unusually brazen and threatening message’.Â
He said: ‘The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.’
Mr Briedis said if the claims made by the hackers are genuine, ‘the critical question will be what information was held there and whether any of it was accessed or downloaded’.
‘At this stage, however, customers shouldn’t assume their personal or payment information has been stolen – that hasn’t been established,’ he said.
‘What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.Â
‘Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.’
He added: ‘But this incident shows how powerful access to a trusted communications channel can be. When an attacker can potentially speak to customers through a company’s own systems, it makes the threat considerably more convincing and potentially much more damaging.’
Cyber security expert Jake Moore described it as ‘one of the most visible hacks in history’ and could ‘put a lot of customer data at risk’.Â
‘By broadcasting their breach directly to Asos app users, the threat actors are likely trying to apply pressure to Asos, showing how extensive their access is so they can leverage some sort of ransom,’ the global cyber security adviser at ESET told the Independent.Â
He said the fact hackers had sent the message through Asos’ app suggests they had gained access to some of the firm’s systems.Â
But Mr Moore said it doesn’t ‘prove their full claims about the extent of the data breach’.Â
Charlotte Wilson, head of enterprise at cyber-security firm Check Point, told the BBC: ‘If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note.’Â
Britain has been hit by several cyber attacks in recent months. In August, up to 1,000 charities, including Breast Cancer UK, English National Ballet and the Molly Rose Foundation, were targeted.Â
Criminals targeted Beacon CRM, which provides customer management software to the charity sector.
It is thought the firm mistakenly published an access key online that allowed hackers to copy its databases.
Meanwhile, M&S and Co-op were left crippled by a cyberattack in the spring and summer of 2025.Â
Notorious hacker group Scattered Spider was linked to the attack that left shelves empty for weeks and forced M&S to stop accepting all online orders and payments.
Have YOU been affected? Email matt.strudwick@dailymail.co.ukÂ
