On Tuesday morning, Asos users across the United Kingdom received pop‑up notifications within the retailer’s app that bore the headline “ASOS HACKED” and displayed the message: “Dear ASOS DPO and IT, we person afloat compromised the Snowflake instance. Engage with us, oregon we volition leak it”. The note also contained a link to a Telegram channel.
Asos responded later that day, stating it had taken immediate steps to curtail the apparent intruders’ access, was conducting an investigation and was working with advisers and relevant authorities on “next steps”. Snowflake, the data‑retention platform referenced in the message, told the BBC that its own inquiry had “found no compromise” of its service.
At this stage the retailer said it is unclear what, if any, data has been accessed. In an evening communication to customers, Asos explained that the breach might expose “basic personal information including name and contact details”, but added that it does not believe any payment‑card details or account passwords have been affected. The company stressed that receipt of the pop‑up does not mean the recipient’s phone has been compromised.
Security experts have offered a series of precautionary measures for anyone who saw the notification:
- Do not click the link; the message directed users to a Telegram channel and both Asos and cyber‑security specialists advise against opening it.
- Change passwords, not only for the Asos account but also for any other services that reuse the same credential. A strong password should combine numbers, symbols, upper‑ and lower‑case letters and should not be duplicated across multiple accounts.
- Enable two‑step verification on critical applications such as banking and email. The National Cyber Security Centre (NCSC) describes this as “one of the most effective ways to protect your online accounts from cyber criminals”. Activation is typically found in the security settings of the respective account.
- Keep a close watch on online transactions for any irregular activity.
Charlotte Wilson, head of enterprise at global cyber‑security firm Check Point, warned that “the biggest immediate risk may be what happens next”. She noted that threat actors are likely to capitalize on the confusion, anticipating “attempts to exploit that confusion”. Her guidance to Asos customers is to avoid being “scared and frightened”, while remaining “extremely suspicious” of any unsolicited emails, texts or messages that claim an account has been compromised, promise a refund or request a password‑reset link.
Kat Cereda, a spokesperson for Which?, advised that anyone receiving a phone call from an individual purporting to represent Asos—or any other organisation—should hang up and contact the company directly through verified channels.
Dr Richard Horne, chief executive of the NCSC, echoed the need for vigilance, urging customers to “stay vigilant to suspicious messages that may seek to take advantage of uncertainty of the breach”. The NCSC’s guidance lists examples such as “official‑sounding messages about ‘resetting passwords’, ‘receiving compensation’, ‘scanning devices’ or ‘missed deliveries’”.
Several questions remain unanswered. It is still unknown who authored the message, what their motive is, how many individuals received the notification or how many may ultimately be affected. Wilson reiterated that there is still “an awful lot” we do not know.
Asos affirmed that its website and app continued to operate “as normal, and customers can continue to shop with confidence on ASOS as normal” as of Tuesday night. The retailer said protecting its customers “is our priority” and promised a further update “as soon as we have confirmed more information”. Users are directed to consult Asos’s official website directly for any forthcoming details.