Finance Crypto Finance Fintech & Transfers Insurance Financial Reporting Banking Budgeting & Planning Auditing & KPIs Financial Planning Accounting Bookkeeping Cost Accounting Financial Statements Accounts Payable & Receivable Auditing Fixed Assets & Depreciation Accounting Software IFRS & GAAP Standards Marketing Brand Strategy Content Marketing SEO & AI Search Social Media Email Marketing Digital Ads TikTok Marketing & Shop Growth Hacking Marketing Analytics Pricing Psychology Brand Ambassadors Tools & Comparisons HR Compensation & Benefits Employee Engagement HR Strategy Recruitment & Talent Acquisition Sales B2B Sales AI in Sales CRM Systems Cold Outreach Pricing Strategy Pipeline Management Sales Enablement Sales Leadership Technology AI Tools & LLMs Cloud Infrastructure Cybersecurity Data Analytics Emerging Tech All β†’ Startup Corporate Governance Law Procurement Procurement: Sourcing Procurement: Vendor Management Procurement: Supply Chain Procurement: Contract Negotiation Procurement: Cost Reduction All Departments
Select Page
⚑ TL;DR
On 6 October 2026, hackers used the Asos app’s own push notification system to send an “ASOS HACKED” extortion message to users. Asos says “basic personal information” such as names and contact details may have been accessed, but it does not believe payment-card data or passwords were affected. Customers should not click the link, should change reused passwords, enable two-step verification and watch for follow-up scams.

Rarely does a cyber-attack announce itself directly on millions of phone screens. On the morning of Tuesday 6 October, at around 10:00 BST, users of the Asos app received a notification headed “ASOS HACKED”. It was addressed not to customers but to the company’s data protection officer and IT team, and it read: “We have fully compromised the Snowflake instance. Engage with us, or we will leak it.” A link to a Telegram channel followed.

Dozens of people told the BBC they received the message. Some thought it was a promotion. Others said it left them scared to open the app. Asos has since confirmed an “unauthorised customer notification” and is investigating. This article sets out what is known, what is still unclear, why experts call the incident significant, and how both customers and businesses should respond.

What happened

According to reporting, Asos told the public on Tuesday afternoon that it was investigating “unauthorised activity” involving third-party platforms it uses. In an email to customers that night, the company apologised, said it had taken immediate action to restrict the apparent hackers’ access, and urged people not to engage with the notification. It stated that its website and app were “operating as usual” and that customers could “shop with confidence” while the investigation continued.

The notification appeared on devices in the UK and, according to local reports, also reached some app users in Australia, France, Sweden and the Republic of Ireland. It is not yet clear how many people received it. For scale, the Asos app has been downloaded more than 10 million times on Android devices alone, and the retailer serves around 17 million customers a year across more than 150 markets.

What data may be involved

On Tuesday evening, Asos told customers that affected information may include “basic personal information including name and contact details”. It added that it does not believe any payment-card information or account passwords have been impacted. At this stage, it is not clear what information, if any, was actually taken, and the company had not, as of the BBC report, informed the UK data regulator, the Information Commissioner’s Office, about any breach.

The hackers’ message referred to a “Snowflake instance”, a reference to a cloud data platform. Snowflake told the BBC that its own investigations had “found no compromise” of its platform. That leaves open the question of how the attackers obtained access, with Asos itself pointing to third-party platforms. Until the investigation concludes, any claim about the technical route is speculation.

Why experts call it a significant moment

Most ransomware and data-extortion attempts happen privately: attackers contact the victim company and make demands away from the public eye. Contacting a company’s customers directly, and using the company’s own app to do it, is rare. BBC cyber correspondent Joe Tidy reported that the tactic may “go down as a significant moment in cyber-attack history”.

Charlotte Wilson, head of enterprise at security firm Check Point, described it as a “deeply serious” and “brazen” attack, saying the hackers had apparently “turned Asos’ own app into their ransom note”. The logic is pressure. If customers see the threat, the company faces reputational damage, media attention and regulatory scrutiny at the same time, which can push it toward negotiation.

The incident also shows the risk created by a company’s third-party tools. Push notification platforms, analytics services and cloud data stores are usually run by external providers and connected through credentials and API keys. If an attacker obtains one of those keys, they can use the same powers the company has: sending messages to every installed app.

πŸ’‘ Pro Tip: A message that appears inside a genuine app is not proof that it is genuine. If a notification asks you to click a link, check the company’s official website or contact channels instead.

What customers should do

The advice from Asos and independent experts is consistent. Receiving the notification does not mean your phone has been hacked. The message came from the app’s notification channel, not from malware on your device. Practical steps:

  • Do not click the link. The notification linked to a Telegram account. Asos and security specialists both advise against engaging.
  • Change your password. Update your Asos password and any other site where you use the same one. Use a long, unique password mixing numbers, symbols and upper and lower case characters.
  • Turn on two-step verification for important accounts such as banking and email. The UK’s National Cyber Security Centre calls it one of the most effective ways to protect online accounts from criminals.
  • Monitor transactions. Keep an eye on your bank and card statements for anything unusual, even though Asos does not believe payment data was affected.
  • Beware of follow-on scams. Wilson warned that “the biggest immediate risk may be what happens next”. Criminals know people are searching for information and may send emails, texts or calls claiming your account has been compromised, offering a refund or asking you to reset a password through a link. Treat any such contact with suspicion and hang up on callers you doubt.

What the Google Trends data suggests

Search behaviour around the incident points to a fast-moving, anxious audience. Within hours, headlines across national outlets, such as “Asos hacked? Customers receive threatening notification from hackers, here’s what we know” and “Clicked on the Asos hacking notification? Don’t panic”, dominated news results. The framing of the questions people ask is practical: is my data safe, what should I do, and should I delete the app?

For publishers and brands alike, the lesson is that people look for reassurance and clear steps, not technical detail. The most useful coverage in these moments leads with action and keeps the uncertainty honest. Pieces that overstate the damage fuel panic; pieces that say nothing leave a vacuum for scammers to fill.

Business lessons: handling a public extortion attempt

Communicate quickly and plainly

Asos acknowledged the issue within hours and followed with an email the same night. Speed matters because customers are already searching for answers. Vague statements invite speculation; specific ones, even if incomplete, build trust.

Be careful about what you claim

Asos said it does not believe payment cards or passwords were affected. That cautious wording is appropriate while an investigation is under way. Absolute promises that later turn out to be wrong cause far greater reputational damage.

Audit third-party access

Because the company pointed to third-party platforms, the incident underlines the need to review which vendors can send messages, read data or hold API credentials. Enforce multi-factor authentication on vendor accounts, rotate keys regularly and limit what each integration can do.

Prepare for the regulator

Under UK data protection law, organisations generally must report qualifying personal-data breaches to the ICO within 72 hours of becoming aware of them. As of the BBC report, Asos had not informed the regulator of any breach, which may reflect that the extent of any data loss is still being established. The coming days will show whether the company concludes a reportable breach has occurred.

Plan for the customer-facing channel

Push notifications, emails and SMS are trusted channels. A security plan should include controls that prevent mass messages without approval, alerts for unusual sending volumes and a rapid way to disable the channel.

Key talking points

  • Hackers sent an “ASOS HACKED” notification through the retailer’s app at about 10:00 BST on 6 October 2026.
  • The message claimed a compromise of a “Snowflake instance” and demanded the company “engage”; Snowflake says its investigations found no compromise of its platform.
  • Asos says names and contact details may have been accessed, but does not believe payment-card details or passwords were affected.
  • The company had not told the UK data regulator of a breach at the time of the BBC report.
  • Experts call the tactic of messaging customers directly rare and brazen.
  • Customers should avoid the link, change reused passwords, use two-step verification and watch for scams.

What to watch next

Key developments to follow: Asos’s findings on how access was obtained and what data was taken; whether it notifies the ICO and customers formally; whether the hackers publish any material on Telegram or elsewhere; and whether scam campaigns exploiting the news appear. The effect on customer trust and on sales will also be a point of interest for a retailer already operating in a competitive, margin-sensitive market.

⚠️ Warning: Do not click links in unexpected messages about this incident, even if they appear to come from Asos. Use the official app store listing or website for updates.

Conclusion

The Asos incident is notable less for what has been confirmed stolen, which so far appears limited to basic personal information at most, than for how the attackers chose to communicate. By turning a retailer’s own app into a megaphone, they changed the dynamics of extortion, moving it from a private negotiation to a public event.

For customers, the response is straightforward and low-cost: do not click, update passwords, enable two-step verification and stay alert. For businesses, the message is that the weakest link may sit in a vendor integration rather than in your own code, and that your most trusted communication channel can become an attacker’s tool. How Asos handles the next few days will be a useful case study in transparency under pressure.

Sources and context: BBC News technology coverage of the Asos notification incident and its customer guidance, plus press headlines surfaced through Google News on 7 October 2026. Details may change as the investigation continues.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading