Asos customers receive ‘hack’ notification threatening leak

Read the original at The Guardian ↗
The Guardian · collected 2026-10-06 · by Sarah Butler

Quick Summary

Asos is investigating claims that a hacker notification sent to customers through the mobile app may indicate a data breach involving their Snowflake cloud platform, which stores sensitive customer information such as transaction records and personal details. Following the notification, Asos shares dropped by nearly 12% on the London Stock Exchange. Security experts warn of potential phishing attacks exploiting concerns over the alleged breach, advising customers to be cautious with communications claiming to come from Asos. This incident follows a series of cyberattacks against other British retailers in recent months, causing disruptions such as stock shortages and website outages.
Written locally by qwen2.5:14b on 2026-10-06, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

On Tuesday morning, ASOS customers received notifications claiming the company had been hacked, with links to a Telegram chat threatening to leak data unless ASOS engaged with them. Snowflake, an online data platform used by many companies to store and analyze customer information, was reportedly compromised according to the alert. Over 400 users reported issues on Downdetector as of 10:30 am. ASOS has approximately 17 million customers in over 150 countries and reported revenues of £2.5 billion for the year ending March 2025. The UK requires companies to report data breaches within three days, informing affected individuals if there is a high risk involved. Shares of ASOS dropped nearly 12% on the London Stock Exchange following these notifications.

Written for “Asos Data Breach Alert” on 2026-10-06, grounded in this article and the 2 other(s) covering the same event.
Why this leaning score
This article does not take a side on a contested political question, so it has no leaning score. That is an answer rather than a gap: a match report or a rescue can be warmly or critically written without being left or right, and scoring it anyway is how approval of a subject gets recorded as a political position.
No political leaning scored for article 59800 · logged 2026-10-06

Signals How these are calculated →

Claims extracted
15
claim-shaped sentences
Uncertain
20%
3 of 15 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
68.4
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
3
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-10-06 · how these are computed

Story

📰 Asos Data Breach Alert
Technology · 3 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 20% of its claims. Each row says how that neighbour differs.
Evening Standard · 0.91 cosine similarity
⚖️ leaning not scored 🔴 0% hedged 0 of 7 📰 publisher trust 67
“Both articles describe the same incident where Asos customers received a notification claiming the company had been hacked, leading to a drop in Asos's share value.”
Evening Standard · 0.91 cosine similarity
⚖️ leaning not scored 🔴 9% hedged 1 of 11 📰 publisher trust 67
“Both articles describe ASOS customers receiving a notification claiming a hack and threatening data leakage, sent via Telegram.”

Publisher

The Guardian · 1355 article(s) · 4 correction(s) detected
Running correction rate · 4 correction(s)
2026-10-03
Tennessee’s top prison official resigning after botched execution of Christa Pike
2026-10-01
Tennessee governor suspends all executions after Christa Pike’s lethal injections fail
2026-09-28
Extra 1,000 prison beds announced in NSW as union warns against arresting ‘our way out of domestic violence’
2026-09-05
Australia’s housing prices are trending down. See which suburbs have had the biggest falls

Who wrote this

Sarah Butler
9 article(s) here · 1 carrying a prediction
🔮 Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”
🔮 People not only want caffeine but iced herbal teas and those drinks that people will drink in the afternoon and evening.”
🔮 Poundland’s management team are in “advanced talks” to lead a rescue bid for the ailing cut-price retailer that could save more than 11,000 jobs.
🔮 The French retailer is set to launch branded areas staffed by Sephora employees in 100 M&S stores and sell through the British retailer’s website in spring next year.
2026-09-29 · assertive framing · M&S links up with Sephora to lure younger shoppers
🔮 Aldi will open 42 stores this year, with 30 opening in the next 10 weeks.
🔮 Instead, the airport hopes to secure planning permission by 2029 and then open the runway “within a decade”, meaning it would not be operational until 2039.
🔮 Andy Burnham said the funds would “help put power back into the hands of locals who know their area best” as part of his effort to “restore pride and bring hope back”.
Also by Sarah Butler
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 9 articles by Sarah Butler →

Topics

Asos Huntress Snowflake Telegram the London Stock Exchange

Subjects

Asos ORG · 6× Asos DPO PERSON · 1× British NORP · 1× Dray Agha PERSON · 1× Huntress ORG · 1× Marijus Briedis PERSON · 1× Marks & Spencer ORG · 1× NordVPN ORG · 1× Telegram ORG · 1× the London Stock Exchange ORG · 1×

Narrative

The value of Asos’s shares on the London Stock Exchange dived almost 12% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service.
framing: assertive · carried by 1 article(s) · first seen 2026-10-06
🔮 Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.”
2026-10-06 · The Guardian
Asos customers receive ‘hack’ notification threatening leak · assertive framing

Claims (15 extracted, 3 hedged)

Asos is investigating after users of its mobile app received a notification claiming hackers had “fully compromised” the online fashion retailer’s data. asserted
hackers → investigate → data
The value of Asos’s shares on the London Stock Exchange dived almost 12% after thousands of customers received a notification titled “Asos hacked” with a link that sent them to the Telegram messaging service. asserted
that → dive → service
The website and app appeared to be continuing to operate on Tuesday morning and it is understood that Asos is still investigating whether any hack has taken place. asserted
hack → appear → place
The message sent out to customers said: “Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance.” asserted
we → send → instance
Snowflake is a cloud platform used to store, process and analyse data including transactions and demographic information such as clothing sizes and body measurements. asserted
Snowflake → use → sizes
It also enables push notifications to clients’ phones. asserted
It → enable → phones
Dray Agha, the senior manager of security operations at Huntress, an online security firm, said: “Snowflake is a massive cloud database where retailers typically store sensitive customer information – it is a real worry if cyber criminals have indeed accessed it as they claim. uncertain
they → say → it
The push notification suggests attackers have breached the systems controlling the Asos mobile app also. uncertain
attackers → suggest → app
“Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation. asserted
Sending → send → negotiation
I strongly advise shoppers to watch out for targeted phishing attempts while we wait for official confirmation of a data breach.” asserted
we → advise → breach
Marijus Briedis, the chief technology officer at the online service provider NordVPN, said: “What customers should be particularly alert to now is what happens next. asserted
what → say → What
High-profile cyber incidents create ideal conditions for phishing attacks. asserted
incidents → create → attacks
Criminals may exploit the publicity by sending emails and texts claiming to be from Asos, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.” uncertain
Criminals → exploit → refund
The potential hack comes after a string of British retailers including Marks & Spencer, the Co-op and Harrods suffered cyber incidents last year. asserted
string → come → incidents
M&S and the Co-op experienced stock shortages and the former was forced to close its website for several weeks as it battled to ensure its systems were clean. asserted
systems → experience → weeks
💬Give feedback
🕘History 🎫Support