Skip to content
Cybersecurity

ASOS Investigates Cyberattack After Hackers Send Messages Through Its App

ASOS customers receive unauthorised notification claiming Snowflake data breach

ASOS Investigates Unauthorised App Activity

ASOS is investigating a suspected cyberattack after an unauthorised notification was sent to customers through its mobile app on October 6. The message, which appeared to come through ASOS's legitimate notification system, claimed that attackers had compromised the company's Snowflake environment and threatened to leak information unless ASOS engaged with them.

ASOS has confirmed unauthorised activity involving third-party platforms it uses to communicate with customers. The company immediately restricted access to the affected notification platforms and brought in internal and external cybersecurity specialists, along with relevant authorities, to investigate.

Hackers Used ASOS's Own Notification Channel

The incident became public after customers began receiving a message titled “ASOS HACKED”. It was addressed to ASOS's data protection officer and IT team rather than customers and included a link to a Telegram channel allegedly operated by the attackers.

The ability to distribute the message through ASOS's own app makes the incident more serious than an unsupported online hacking claim. However, it does not by itself prove that the attackers gained access to ASOS's main databases or stole the data they claimed to have obtained.

Security researchers have also noted that ASOS uses third-party marketing and customer-engagement systems connected to Snowflake, meaning the notification access and the alleged database compromise could involve related but separate systems.

Customer Information May Have Been Accessed

ASOS said its investigation currently indicates that basic personal information, including names and contact details, may have been accessed. The retailer does not believe payment-card information or account passwords were affected.

The UK's National Cyber Security Centre has advised ASOS customers to assume they may be affected, even if they did not receive the unauthorised notification. It also warned users to watch for suspicious messages that could follow the incident and avoid clicking unfamiliar links.

ASOS, however, says customers do not currently need to change their passwords and should simply disregard the unauthorised notification and avoid interacting with its external link.

Snowflake Breach Claim Remains Unverified

The alleged attackers specifically claimed they had “fully compromised” an ASOS Snowflake instance. Snowflake has said it has found no evidence that its platform itself was breached. The claim therefore remains part of the ongoing investigation rather than a confirmed finding.

This distinction matters because accessing a company's notification or marketing infrastructure does not automatically provide access to its underlying cloud data. Investigators will need to establish how the attackers obtained the ability to send messages through ASOS's app and whether that access extended into customer data systems.

ASOS Platforms Remain Operational

ASOS said its website and app continue to operate normally, with no current disruption to its retail operations. The company has restricted access to the communication platforms involved while the investigation continues.

The incident nevertheless demonstrates the security risks created by interconnected customer-engagement systems. A compromise of a trusted communication channel can give attackers a way to reach customers directly under a company's identity, potentially creating a second wave of phishing or social-engineering attacks even if the underlying data breach proves limited.

ASOS has not yet established the full scope of the incident. The company is expected to provide further information as its investigation progresses.