E-commerce
ASOS warns customer data may have been accessed in cyberattack
ASOS shares fell as much as 15% after customers received an unauthorised notification threatening to release their data.
By Sophie Callaghan, Retail & E-commerce Reporter ·

ASOS has warned that customers’ personal details may have been accessed in a cyberattack after thousands received an unauthorised message on 6 October, with shares in the online fashion retailer falling as much as 15% that day.
The company said it did not believe payment-card details or passwords had been accessed. Its confirmation that some personal information could have been exposed followed a notification sent to customers that morning, as reported by InternetRetailing.
What happened
The pop-up reached thousands of ASOS customers and mobile app users and purported to come from attackers. It claimed they had gained complete access to the retailer’s Snowflake instance and threatened to release data unless ASOS engaged with them.
ASOS confirmed that the customer notification was unauthorised. That established that the message had not been a legitimate company communication, but did not substantiate the attackers’ wider claims about their access.
Snowflake, the data storage company named in the threat, opened an investigation after learning about the notification. It said its work had found no compromise of the Snowflake platform, while stressing that enquiries remained under way.
The distinction is important to the account of the incident: the attackers claimed access to an ASOS instance, while Snowflake’s statement addressed the security of its platform. Neither statement established the full extent of any customer data exposure.
The background
Some customers criticised the time ASOS took to respond. The retailer issued its first statement several hours after the reported breach, leaving a gap between customers receiving the threat and the company publicly addressing it.
The share price decline followed reports of the possible data breach. The fall of as much as 15% was an intraday movement on 6 October, rather than a stated closing loss.
A previous disputed breach claim provided a comparison for Boris Cipot, principal security engineer at Black Duck. He pointed to an incident earlier in the year in which a group claimed to have obtained sensitive customer information from Synopsys.
Synopsys said its investigation had found no evidence of unauthorised access to its systems or customers’ technical data. Cipot used that case to explain why an attacker’s account should be tested against evidence rather than accepted at face value.
What people are saying
Charlotte Wilson, head of enterprise for the UK and Ireland at Check Point, said the incident challenged the trust customers place in notifications delivered through company apps. People generally expect those messages to originate with the business itself, she said.
Wilson argued that a possible takeover of that communication channel could rapidly turn a technical security problem into a public reputational issue, with consequences for a company’s market value. Her concern centred on the attackers apparently reaching customers directly through a channel associated with ASOS.
An unnamed cybersecurity expert suggested that the public threat might represent an escalation after earlier approaches had been ignored. The expert noted that cyber-extortion demands are usually made privately. That explanation remained a possibility, not an established account of what happened at ASOS.
Cipot advised the retailer to focus on containment and investigation while taking the threat seriously. He distinguished between responding to a potentially significant incident and treating the attackers’ assertions as verified facts.
For customers, his advice was to avoid the Telegram link associated with the message and be especially cautious about emails, texts and other communications appearing to come from ASOS.
What happens next
Snowflake said it would provide further updates when more information became available. Its investigation was continuing at the time of the report.
The attackers had not been identified, and the full motive behind the apparent hack remained unknown. Establishing what information, if any, was accessed beyond the personal details flagged by ASOS remained an unresolved part of the incident.
Why this matters
For UK business owners and directors, the ASOS incident puts customer communications alongside data security as an immediate operational concern. An unauthorised app notification reached thousands of people, customers criticised the response time and shares fell as much as 15%. The case also underlines the need to distinguish attackers’ claims from investigation findings: ASOS warned of possible personal data exposure, while Snowflake reported no compromise of its platform. Containment and evidence-led communication remain the priorities identified by the security specialists.
Frequently asked questions
- What happened in the ASOS cyberattack?
- Thousands of ASOS customers and app users received an unauthorised notification on 6 October. The message purported to come from attackers and threatened to release customer data unless the retailer engaged with them.
- Was ASOS customer data accessed?
- ASOS said basic personal information may have been accessed. The full extent of any exposure had not been established in the report.
- Were ASOS passwords or payment details stolen?
- ASOS said it did not believe payment-card information or passwords had been accessed. That was the retailer’s assessment at the time of its statement.
- Was Snowflake hacked in the ASOS incident?
- The attackers claimed complete access to ASOS’s Snowflake instance. Snowflake said its investigation had found no compromise of its platform, although enquiries were continuing.
- How much did ASOS shares fall after the cyberattack?
- ASOS shares fell as much as 15% during trading on 6 October following reports of the possible data breach.
- What should ASOS customers do after the notification?
- Black Duck security engineer Boris Cipot advised customers not to click the Telegram link and to be particularly cautious about emails, texts or other messages appearing to come from ASOS.
- Who was behind the ASOS cyberattack?
- The attackers’ identity was unknown at the time of the report. Their full motive had also not been established.
In this story
Topics: ASOS cyberattack · ASOS data breach · ASOS customer data · ASOS app notification · ASOS Snowflake · ASOS share price fall · All E-commerce news →
Original reporting: InternetRetailing. This article is an independent write-up by British Business Echo.
Latest from the newsdesk
- Banking & Lending
Volkswagen finance arm posts loss after £725m redress provision
- AI in Business
HSBC weighs cuts to up to 70% of UK wealth adviser roles
- Funding & Business Finance
Konsileo secures £5m to support broker and platform growth
- Business Regulation
UK T+1 settlement: firms face December readiness milestones
- Mergers & Acquisitions
Brave Bison makes final £53.4m offer for System1
