Skip to main content
Become a TechRadar Insider
- Join our community
Weekly newsletters
Get daily news, weekly deals and the week’s top tech stories
Commenting access
Join the conversation, share your thoughts and get expert advice
Member badges
Earn badges as you explore news, deals, reviews, guides and more
Exclusive deals
Save on gadgets, subscriptions and accessories with handpicked discounts
Become a TechRadar Insider
Sign up with your email below to instantly access member features, newsletters and exclusive Insider perks
By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Welcome to Tech Radar club !
Hi ,

Keep exploring and earning more as a member.


Earn your first badge
Start reading to unlock your first badge
Keep earning badges
Explore ways to get more involved as a member.

Your membership perks

Start exploring exclusive deals, expert advice and more

Member Rewards

Unlock and manage exclusive Techradar member rewards.

See rewards

ASOS 'hacked' alert live — all the latest from security experts as customers receive threatening message

The latest on a scary morning for ASOS customers

A phone showing the ASOS app download page
(Image credit: © Getty Images)

The online shopping giant ASOS has seemingly been hacked today, with customers receiving a threatening notification from the mobile app.

The message (titled "ASOS HACKED") was sent on Tuesday morning via a push alert in the ASOS app and security experts have told us that "the potential scope is significant". We've contacted ASOS, but so far it hasn't publicly commented on the issue.

You can follow all the latest developments live with us, including the latest advice on what you should do if you're one of the site's 17 million global customers...

Potential ASOS hack — the latest news

  • ASOS customers reported receiving a threatening alert on Tuesday morning
  • The alert was titled 'ASOS Hacked' and linked out to a Telegram chat
  • ASOS hasn't yet officially commented on the security issue

ASOS statement on hack

More now from ASOS.

The company has confirmed that an "unauthorised customer notification" was sent to ASOS app users at around 10am this morning.

"We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities," the company statement says.

ASOS further stated that "Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords, were impacted."

Customer advice: watch out for fake ASOS communications

“High-profile cyber incidents create ideal conditions for phishing attacks. Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund. “Don't click links in unexpected messages, even if they look convincing. Go directly to the ASOS app or website instead. Customers should also make sure their ASOS password is unique and, if they've used the same password elsewhere, change it on those accounts too. This incident shows how powerful access to a trusted communications channel can be. When an attacker can potentially speak to customers through a company's own systems, it makes the threat considerably more convincing and potentially much more damaging.”

Marijus Briedis, Chief Technology Officer at NordVPN

NordVPN with NordPass ($4.49 per month)
Like ExpressVPN, NordVPN also has a password manager if you select the middle tier plan. We rate NordVPN as the best VPN available and we also NordPass as the best password manager too, so this is something of a winning combination. NordVPN comes with a built-in antivirus which spots scams, phising attacks and fake shops. So, if you are concerned about your details in this alleged ASOS hack, then NordVPN is a very good choice for bolting the door shut on your personal details and bank accounts. Try it with the full 30-day money-back guarantee.

ASOS customer advice: change your password and get a password manager

"Getting a message like that from an app you trust is genuinely unsettling. Most people think of a hack as something that happens out of sight, so seeing a threat land on your own phone makes it feel much more personal. It's completely understandable that people are worried, but the most important thing right now is not to panic. At times like this, panic can make matters much worse. What people can do is some simple due diligence. Don't tap on the notification or follow the link in it. Go to the ASOS website directly, by typing in the address yourself rather than through an email or the app, and reset your password. If the attackers have compromised that side of things, they may already have your old password, and if they're still inside they could potentially see the new one too. But it's a quick, simple step that should, in general, draw a line under it. What's more critical is everywhere else you've used that password. Everyone knows they shouldn't reuse passwords, but it happens. If attackers have your password, you can guarantee they'll try it in every lock they can find. So take this as a wake-up call to finally get a password manager and start updating your passwords. If nothing was leaked, great, you've still massively upgraded your security against future attacks. And if it was, you've slammed the door shut before anyone could take advantage. Either way, it's a win-win."

Dr. Pete Membrey, Chief Research Officer at ExpressVPN

ExpressVPN Advanced with ExpressKeys: $4.49 per month
It's no accident that Dr. Pete Membrey is talking password managers. That's because ExpressVPN Advanced comes with access to the company's ExpressKeys which allows you to store, generate and autofill an unlimited amount of hard to crack passwords. You can find our list of best password managers here. And you can sign up for ExpressVPN just here.

The lack of any additional information and the (short) presentation of a group suggests that the threat actor is planning to claim more attacks. It may be worth monitoring; despite the potential low technological complexity of this attack, it is something visible to a large population and will result in media attention. By exploiting the obtained attention, threat actors may follow up with more, potentially similar attacks.

Michele Campobasso, senior security researcher at Forescout

The attackers didn't just steal from ASOS. They used ASOS's own voice to tell its customers about it. That's not just a data breach. That's a complete loss of operational control, and the reputational damage from that alone is significant.

Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress

Now is not the time for Asos customers to panic because so little is known about the severity of the reported data breach. Its best to never open notifications from retailers in texts or emails and never click on any of the links received. Customers should go directly to the Asos website for more information about the breach. For all organisations, this breach is another reminder about the importance of adopting an assume breach mindset because incidents will inevitably occur and no company is immune to being attacked. Overall, companies that prepare in advance of incidents improve their chances of minimising disruptions to their business. In addition, it doesn’t pay to pay ransoms because not only does it further fuel the ransomware economy, but it doesn’t guarantee the threat group will hand over decryption keys upon payment. Maintaining strong backups and scheduling tabletop exercises regularly is extremely important. Organisations should also have a crisis response plan available to activate during cyber related incidents that ties back to regularly scheduling table top exercises, so stakeholders are familiar with the initial steps and actions to deploy when an incident is discovered

Jeff Wichman, Senior Director of Breach Preparedness and Response at Semperis

Snowflake is a data analysis and AI platform used by several organizations. In 2024, ShinyHunters hacked Snowflake instances of over 160 organizations and stole sensitive data that was used for extortion. They used credentials obtained from infostealers for initial access. This recent hack may be similar, although it is not confirmed what the initial access was. Snowflake has published more than 20 vulnerabilities on their products in 2026, including three considered high criticality in September, but none of those is known to be exploited by threat actors. The threat actors provided a link to a Telegram channel created today that already has 150+ subscribers. That channel then links to a group chat with more than 260 participants. "Xuanye" is not a known threat actor, but the name is of Chinese origin, which could indicate a Chinese-speaking threat actor or simply a false flag

Daniel dos Santos, VP of research at Forescout

Snowflake is a massive cloud database where retailers typically store sensitive customer information, a real worry if cyber criminals have indeed accessed it as they claim. The push notification suggests attackers have breached the systems controlling the ASOS mobile app also. This is clear public extortion. Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.

Dray Agha, senior manager of security operations at Huntress

It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access

Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes

What should you do?

Did you get the ASOS 'hacked' notification? If so, there are a few important things that you shouldn't do, including clicking the Telegram link in the message. You should also:

  • Avoid clicking links in any suspicious emails
  • Do not click links in any suspicious texts or messages

Other cybercriminals could try to exploit the hysteria caused by the ASOS notification, so you should be particularly wary of emails telling you your account has been compromised, or asking you to reset your password.

It's also wise to be careful about shopping on ASOS until the company comments publicly on the issue, which hasn't happened yet.

What did the alert say?

ASOS customers first reported receiving the push alert above on Tuesday morning at around 4.55am ET / 9.55am BST.

This coincided with a spike in reports on Downdetector. The message is addressed to ASOS' data protection officer (DPO) and IT team, but was sent to customers.

The 'Snowflake' the message refers to is a Software-as-a-Service (SaaS) that organizations use as a dedicated cloud environment to store, process, and analyze data. This is what has concerned security experts, although it's a little early to say whether customer data has been compromised.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.