On 6 October 2026, hackers used the Asos app’s own push notification system to send an “ASOS HACKED” extortion message to users. Asos says “basic personal information” such as names and contact details may have been accessed, but it does not believe payment-card data or passwords were affected. Customers should not click the link, should change reused passwords, enable two-step verification and watch for follow-up scams.
Rarely does a cyber-attack announce itself directly on millions of phone screens. On the morning of Tuesday 6 October, at around 10:00 BST, users of the Asos app received a notification headed “ASOS HACKED”. It was addressed not to customers but to the company’s data protection officer and IT team, and it read: “We have fully compromised the Snowflake instance. Engage with us, or we will leak it.” A link to a Telegram channel followed.
Dozens of people told the BBC they received the message. Some thought it was a promotion. Others said it left them scared to open the app. Asos has since confirmed an “unauthorised customer notification” and is investigating. This article sets out what is known, what is still unclear, why experts call the incident significant, and how both customers and businesses should respond.
What happened
According to reporting, Asos told the public on Tuesday afternoon that it was investigating “unauthorised activity” involving third-party platforms it uses. In an email to customers that night, the company apologised, said it had taken immediate action to restrict the apparent hackers’ access, and urged people not to engage with the notification. It stated that its website and app were “operating as usual” and that customers could “shop with confidence” while the investigation continued.
The notification appeared on devices in the UK and, according to local reports, also reached some app users in Australia, France, Sweden and the Republic of Ireland. It is not yet clear how many people received it. For scale, the Asos app has been downloaded more than 10 million times on Android devices alone, and the retailer serves around 17 million customers a year across more than 150 markets.
What data may be involved
On Tuesday evening, Asos told customers that affected information may include “basic personal information including name and contact details”. It added that it does not believe any payment-card information or account passwords have been impacted. At this stage, it is not clear what information, if any, was actually taken, and the company had not, as of the BBC report, informed the UK data regulator, the Information Commissioner’s Office, about any breach.
The hackers’ message referred to a “Snowflake instance”, a reference to a cloud data platform. Snowflake told the BBC that its own investigations had “found no compromise” of its platform. That leaves open the question of how the attackers obtained access, with Asos itself pointing to third-party platforms. Until the investigation concludes, any claim about the technical route is speculation.
Why experts call it a significant moment
Most ransomware and data-extortion attempts happen privately: attackers contact the victim company and make demands away from the public eye. Contacting a company’s customers directly, and using the company’s own app to do it, is rare. BBC cyber correspondent Joe Tidy reported that the tactic may “go down as a significant moment in cyber-attack history”.
Charlotte Wilson, head of enterprise at security firm Check Point, described it as a “deeply serious” and “brazen” attack, saying the hackers had apparently “turned Asos’ own app into their ransom note”. The logic is pressure. If customers see the threat, the company faces reputational damage, media attention and regulatory scrutiny at the same time, which can push it toward negotiation.
The incident also shows the risk created by a company’s third-party tools. Push notification platforms, analytics services and cloud data stores are usually run by external providers and connected through credentials and API keys. If an attacker obtains one of those keys, they can use the same powers the company has: sending messages to every installed app.
What customers should do
The advice from Asos and independent experts is consistent. Receiving the notification does not mean your phone has been hacked. The message came from the app’s notification channel, not from malware on your device. Practical steps:
- Do not click the link. The notification linked to a Telegram account. Asos and security specialists both advise against engaging.
- Change your password. Update your Asos password and any other site where you use the same one. Use a long, unique password mixing numbers, symbols and upper and lower case characters.
- Turn on two-step verification for important accounts such as banking and email. The UK’s National Cyber Security Centre calls it one of the most effective ways to protect online accounts from criminals.
- Monitor transactions. Keep an eye on your bank and card statements for anything unusual, even though Asos does not believe payment data was affected.
- Beware of follow-on scams. Wilson warned that “the biggest immediate risk may be what happens next”. Criminals know people are searching for information and may send emails, texts or calls claiming your account has been compromised, offering a refund or asking you to reset a password through a link. Treat any such contact with suspicion and hang up on callers you doubt.
What the Google Trends data suggests
Search behaviour around the incident points to a fast-moving, anxious audience. Within hours, headlines across national outlets, such as “Asos hacked? Customers receive threatening notification from hackers, here’s what we know” and “Clicked on the Asos hacking notification? Don’t panic”, dominated news results. The framing of the questions people ask is practical: is my data safe, what should I do, and should I delete the app?
For publishers and brands alike, the lesson is that people look for reassurance and clear steps, not technical detail. The most useful coverage in these moments leads with action and keeps the uncertainty honest. Pieces that overstate the damage fuel panic; pieces that say nothing leave a vacuum for scammers to fill.
Business lessons: handling a public extortion attempt
Communicate quickly and plainly
Asos acknowledged the issue within hours and followed with an email the same night. Speed matters because customers are already searching for answers. Vague statements invite speculation; specific ones, even if incomplete, build trust.
Be careful about what you claim
Asos said it does not believe payment cards or passwords were affected. That cautious wording is appropriate while an investigation is under way. Absolute promises that later turn out to be wrong cause far greater reputational damage.
Audit third-party access
Because the company pointed to third-party platforms, the incident underlines the need to review which vendors can send messages, read data or hold API credentials. Enforce multi-factor authentication on vendor accounts, rotate keys regularly and limit what each integration can do.
Prepare for the regulator
Under UK data protection law, organisations generally must report qualifying personal-data breaches to the ICO within 72 hours of becoming aware of them. As of the BBC report, Asos had not informed the regulator of any breach, which may reflect that the extent of any data loss is still being established. The coming days will show whether the company concludes a reportable breach has occurred.
Plan for the customer-facing channel
Push notifications, emails and SMS are trusted channels. A security plan should include controls that prevent mass messages without approval, alerts for unusual sending volumes and a rapid way to disable the channel.
Key talking points
- Hackers sent an “ASOS HACKED” notification through the retailer’s app at about 10:00 BST on 6 October 2026.
- The message claimed a compromise of a “Snowflake instance” and demanded the company “engage”; Snowflake says its investigations found no compromise of its platform.
- Asos says names and contact details may have been accessed, but does not believe payment-card details or passwords were affected.
- The company had not told the UK data regulator of a breach at the time of the BBC report.
- Experts call the tactic of messaging customers directly rare and brazen.
- Customers should avoid the link, change reused passwords, use two-step verification and watch for scams.
What to watch next
Key developments to follow: Asos’s findings on how access was obtained and what data was taken; whether it notifies the ICO and customers formally; whether the hackers publish any material on Telegram or elsewhere; and whether scam campaigns exploiting the news appear. The effect on customer trust and on sales will also be a point of interest for a retailer already operating in a competitive, margin-sensitive market.
Conclusion
The Asos incident is notable less for what has been confirmed stolen, which so far appears limited to basic personal information at most, than for how the attackers chose to communicate. By turning a retailer’s own app into a megaphone, they changed the dynamics of extortion, moving it from a private negotiation to a public event.
For customers, the response is straightforward and low-cost: do not click, update passwords, enable two-step verification and stay alert. For businesses, the message is that the weakest link may sit in a vendor integration rather than in your own code, and that your most trusted communication channel can become an attacker’s tool. How Asos handles the next few days will be a useful case study in transparency under pressure.
Sources and context: BBC News technology coverage of the Asos notification incident and its customer guidance, plus press headlines surfaced through Google News on 7 October 2026. Details may change as the investigation continues.
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.
