On October 6, UK online fashion retailer ASOS announced it was investigating unauthorized activity involving third-party platforms after customers received alerts suggesting a hack. The company stated that personal information such as names and contact details may have been accessed but assured that payment card data and account passwords were not compromised. Asos’s stock initially dropped by nearly 15% in London before partially recovering, ending the day down about 10%.
Written locally by qwen2.5:14b on 2026-10-06,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
On Tuesday morning, ASOS customers received a phone alert stating that the company had been hacked. The message linked to a Telegram chat threatening ASOS's data protection officer (DPO) and IT departments, demanding engagement or else they would leak customer data stored on Snowflake, an online data platform used by many companies to store sensitive information. This led to concerns among over 400 customers reporting issues with the app and website on Downdetector. ASOS has around 17 million customers globally and reported revenues of £2.5 billion in 2025, making this incident particularly alarming due to potential financial impacts. Shares in ASOS fell by more than 10%, reflecting market concerns over data security. The company confirmed it is investigating "unauthorized activity" but does not believe payment card information or account passwords were compromised; however, personal details such as names and contact information may have been accessed. This incident follows a trend of cyberattacks targeting UK retailers including Marks & Spencer and Harrods in recent years.
Written for “Asos Hacked Alert Customers” on 2026-10-06,
grounded in this article and the 8 other(s) covering the same event.
Online fashion giant Asos probes ‘unauthorised activity’ after hacking phone alerts
AI generated
asserted
Asos → probe → alerts
UK online fashion giant Asos said on Oct 6 it was investigating “unauthorised activity involving third-party platforms” after its customers received a phone alert saying the retailer had been hacked.
asserted
retailer → say → alert
Asos, which has 17 million active customers worldwide, said personal information like names and contact details “may have been accessed” but that it did not believe payment card information or account passwords were impacted.
The company noted its website and app were operating normally following the incident, which prompted its share price to slump initially by almost 15% in London.
uncertain
which → have → London
Shares in the company had partially recovered by mid-afternoon but were still down on Oct 6 by nearly 10%.
asserted
Shares → recover → %
“We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers,” Asos said in a statement.
asserted
Asos → investigate → statement
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
asserted
We → take → advisers
Customers had received a mobile app notification titled “Asos hacked” and directing them to a Telegram account.
asserted
Customers → receive → account
“Dear Asos DPO and IT, we have fully compromised your Snowflake instance.
asserted
we → compromise → instance
Engage with us, or we will leak it,” read the notification, according to screenshots shared on social media and reported by British media.
uncertain
notification → engage → media
DPO stands for data protection officer, while Snowflake is a US company that provides its clients with a cloud-based platform for data storage, management and analysis.
asserted
that → stand → storage
In a statement shared with AFP, a Snowflake spokesperson said the firm began an investigation as soon as it became aware of the reported notification.
asserted
it → share → notification
“At this time, we can report that we have found no compromise of the Snowflake platform,” the statement added.
asserted
statement → report → platform
“We take customer privacy and security very seriously.
asserted
We → take → privacy
The investigation is ongoing, and we will provide further updates as soon as more information becomes available.”
‘Panic’ aim
This kind of notification, which amounts to “psychological warfare”, is “designed to whip up panic”
asserted
which → provide → panic
, said Marie Wilcox, market strategy analyst at cybersecurity firm Binalyze.
asserted
Wilcox → say → Binalyze
The attackers reasoned that “any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response,” she said.
asserted
she → reason → response
Britain’s state-run National Cyber Security Centre (NCSC) has offered Asos assistance, according to sources.
uncertain
Centre → run → sources
A spokesperson for the country’s data watchdog, the Information Commission Office, said it did not appear “to have received a report on this matter at this stage”.
asserted
it → say → stage
Asos told shareholders it has cyber security insurance with a large provider and that it was “too early” to quantify any potential impact on its trading, Britain’s Press Association news agency reported.
asserted
agency → tell → trading
Founded in 2000, Asos generated £2.48 billion (S$3.1 billion) in revenue while posting net losses of £298 million in the 12 months to the end of August 2025.
asserted
Asos → found → August
Its own brands account for 40% of the value of goods sold on the platform, compared to 60% for partner brands.
asserted
brands → account → brands
In 2025, the UK was hit by a wave of cyberattacks targeting, among others, Jaguar Land Rover, Marks & Spencer, the department store Harrods and the Co-op food chain.
asserted
UK → hit → Rover
And three British airports belonging to the Manchester Airports Group were targeted by an attack in August that resulted in the theft of personal data belonging to 8.7 million customers.
asserted
that → belong → customers