ASOS data breach: what we know and what to do now
The ASOS data breach is confirmed after a rogue app alert. What ASOS says was taken, what the hackers claim, and how to protect yourself from phishing.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

The ASOS data breach is confirmed: the UK online fashion retailer says attackers got into third-party platforms it uses to talk to customers and took names and contact details, after a group calling itself "Xuanye Group" sent an extortion message to shoppers through the ASOS app on Tuesday, October 6, 2026. ASOS says payment cards and account passwords were not accessed. The hackers say much more. Here is what each side has actually said, kept apart, and what you should do if you shop with ASOS.
Key takeaways
- Confirmed by ASOS: an employee account was taken over through social engineering, and those credentials opened third-party platforms holding customer names and contact details.
- Not affected, according to ASOS: payment card information and account passwords. The company says there is no action you need to take on your account.
- Claimed, not confirmed: the group says it "fully compromised" ASOS data hosted on Snowflake. Snowflake says it found no compromise of its own platform, and ASOS has not named Snowflake.
- Unknown: how many of ASOS's roughly 17 million customers are affected.
- The real risk now is phishing: the UK's cyber agency says every ASOS customer should assume they're affected and watch for scam messages.
What ASOS has confirmed about the data breach
The alert landed first. On October 6, some ASOS app users got a push notification titled "Asos hacked," addressed to the company's data protection officer and IT department, that pointed to a Telegram channel. The same day, ASOS said it was investigating unauthorized activity involving third-party platforms it uses to contact customers, had restricted access to them, and believed "basic personal information including name and contact details may have been accessed," Reuters reported. ASOS shares fell about 10% that day, and the company told investors it holds cyber insurance but that it was too early to put a number on any hit to trading.
By October 8 the "may have" had become a confirmation. In a filing with the London Stock Exchange, ASOS said hackers broke into a third-party platform hosting data it uses to communicate with customers and took names and contact information, as TechCrunch reports. In a security notice quoted by BleepingComputer, ASOS explained how: someone "gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," then used them on "certain third-party platforms used by ASOS."
According to that notice, the exposed data is full names, contact details and "certain non-personal account-related information." BBC News, as cited by TechCrunch, reported a fuller list: home addresses, phone numbers, email addresses and notes on customer profiles such as website searches. ASOS has not said how many customers are in the data; TechCrunch notes the company counts about 17 million customers on its website.
What the hackers claim
Everything in this section comes from the attackers and has not been verified by ASOS or anyone else.
- Who: a group calling itself Xuanye Group, named in the Telegram channel the notification linked to.
- What they say they have: the notification claimed "we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
- What they say they didn't take: payment information, which they say "is not affected," adding that the app "is safe to use."
- What they haven't said: how much data they hold. TechCrunch notes they have not given a figure.
The message reads as an extortion demand aimed at the company, delivered through its own customers' phones.
Where Snowflake fits
Snowflake is a cloud data platform that companies use to store and analyze large amounts of business data. After the notification named it, Snowflake opened an investigation and told Reuters: "At this time, we can report that we have found no compromise of the Snowflake platform." That is consistent with ASOS's own account, which puts the entry point at a stolen employee login and describes no flaw in any vendor's systems.
There is a precedent. In 2024, Google's Mandiant reported that a group stole data from Snowflake customers by logging in with credentials taken by infostealer malware, on accounts without multi-factor authentication; Mandiant and Snowflake notified about 165 organizations, and Mandiant found no breach of Snowflake's own environment. TechCrunch notes it is not known whether the ASOS instance had multi-factor authentication switched on. Stolen logins are behind other incidents this week too, like the FortiBleed attacks on FortiGate firewalls.
What ASOS customers should do now
ASOS says there is no action you need to take on your account. The UK's National Cyber Security Centre goes further: its alert for ASOS customers says you should assume you're affected even if you never saw the notification, because scam messages can arrive some time after a breach. Leaked names and contact details are exactly what makes a fake "ASOS refund" or "order problem" message look real.
- Distrust anything asking for secrets. ASOS says it will never ask for passwords, security codes or payment details through an unsolicited message or call.
- Don't tap links in unexpected messages, push notifications included. This attack proved a notification from the genuine app can be fake. Open the app or type the address yourself.
- Fix reused passwords. ASOS says passwords weren't taken, but if your ASOS password also protects your email or bank, change it there. The NCSC recommends passkeys, or strong separate passwords plus two-step verification.
- Keep watching. Leaked contact details don't expire, so a scam can arrive well after the news fades. The Denmark CPR data breach shows how leaked names and addresses get reused to make scams convincing.
What happens next
ASOS says its investigation is ongoing, with outside experts, law enforcement and regulators, and that it has added security measures. Still open in the ASOS data breach: how many customers are affected, which platform held the data, how the attackers reached the push notification system, and whether Xuanye Group publishes anything. For another attack that abused infrastructure people trust, see how attackers hijacked country domain registries this week.
Bottom line
ASOS has confirmed that names and contact details were taken after an employee was tricked out of a login, and it says cards and passwords are safe. The Snowflake claim and the scale of the theft are still the hackers' word. If you shop with ASOS, the practical step is the same either way: treat unexpected "ASOS" messages as suspect, and make sure no important account shares your ASOS password.
FAQ
Was my ASOS password stolen?
ASOS says account passwords and payment card information were not accessed. Its own statements only confirm names, contact details and some non-personal account information. If you reused your ASOS password elsewhere, changing it on those other accounts is a cheap precaution.
Is the ASOS app safe to use?
ASOS says its website and app were and remain safe to use, and it restricted access to the notification platforms the attackers abused. Treat any unexpected push notification or message with a link as suspect, even if it seems to come from the app.
How many ASOS customers were affected?
ASOS has not said. The company has about 17 million customers, and the UK's National Cyber Security Centre advises every ASOS customer to assume they are affected.
Was Snowflake hacked?
Snowflake says it found no compromise of its platform. ASOS links the breach to a stolen employee login used on third-party platforms and has not confirmed the hackers' claim about Snowflake.