Asos issued an apology to its 16.5 million customers after some users received a push notification claiming the company had been hacked, though it was later revealed that Asos itself did not believe the notification was legitimate. The company is investigating “unauthorized activity” involving third-party platforms and stated that personal information like names and contact details may have been accessed but does not think payment card information or account passwords were compromised. As part of its response, Asos is working with cybersecurity experts and authorities while emphasizing that their website and app are functioning normally. The National Cyber Security Centre has offered assistance in the investigation.
Written locally by qwen2.5:14b on 2026-10-06,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
On Tuesday morning, ASOS customers received a phone alert claiming the company had been hacked. The hackers allegedly compromised the Snowflake data platform used by ASOS for storing and analyzing customer information. This led to a 10-12% drop in ASOS’s share prices on the London Stock Exchange and raised concerns among over 400 customers reported issues with the app and website. While ASOS confirmed it is investigating unauthorized activity involving third-party platforms, they do not believe payment card details or account passwords were impacted but acknowledged that personal information such as names and contact details may have been accessed. Snowflake stated its platform was unaffected by the alleged breach. This incident highlights growing cyber threats faced by UK retailers like Marks & Spencer and Harrods in recent years.
Written for “ASOS Hacked Incident” on 2026-10-06,
grounded in this article and the 11 other(s) covering the same event.
Asos has apologised to customers who were sent a phone alert saying the online retailer had been hacked.
asserted
retailer → apologise → alert
The fashion giant said it is investigating “unauthorised activity” involving a third-party platform and urged customers to disregard the notification and not click it or any links on it.
asserted
it → say → it
The online retailer, which has 16.5 million customers, said personal informational, such as names and contact details, “may have been accessed” as a result.
uncertain
informational → have → result
However, the company said it does not “believe that payment card information or account passwords, were impacted”.
asserted
information → say → ?
In an email to customers on Tuesday evening, the firm told customers: “We’re sorry that you may have received an unauthorised push notification from us earlier today.
uncertain
you → tell → us
“Please disregard the notification and do not click or engage with the external third-party link it contained.”
asserted
it → disregard → link
Later on Tuesday, the company confirmed that an “unauthorised customer notification” had been sent out through its mobile app.
asserted
notification → confirm → app
In a statement, the company said: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.
asserted
we → say → customers
“We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.
asserted
We → take → advisers
Read More
“Our website and app are operating as normal, with no current disruption to any aspects of our operations.
asserted
website → read → operations
“Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”
asserted
update → change → us
The National Cyber Security Centre (NCSC), a part of GCHQ, has offered Asos assistance.
asserted
Centre → offer → assistance
The notification message sent out by cyber attackers refers to cloud firm Snowflake, which stores data for many major companies.
asserted
which → send → companies
Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message.
“The investigation is ongoing and we will provide further updates as soon as more information becomes available,” a spokeswoman added.
asserted
spokeswoman → say → updates
Asos told shareholders it has cyber security insurance with a large provider and said it is “too early” to quantify any potential impact on its trading.
asserted
it → tell → trading
The UK is the group’s largest market, representing 49% of all revenues in the first half of the latest financial year.
asserted
UK → represent → year
The fast fashion firm is currently undergoing a major turnaround programme in a bid to halt declining sales and return to profit.
asserted
firm → undergo → profit
It comes after raft of UK retailers were targeted by cyber attackers over the past two years, including Marks & Spencer and Harrods.
asserted
raft → come → Marks
Dr Richard Horne, chief executive of the NCSC, said: “The unauthorised notification sent out to Asos customers has brought into the light how cyber incidents do not simply affect big business but can have repercussions for individuals much more widely too.
asserted
incidents → say → individuals
“The NCSC has been in contact with Asos today to offer our support as the company investigates what has taken place.
asserted
what → offer → place
“Individuals who received the notification should not click on any suspicious links and should stay vigilant to suspicious messages that may seek to take advantage of news of the breach.
uncertain
that → receive → breach
“If you are worried about your personal data being impacted, we recommend following the advice set out at ncsc.gov.uk to help stay safe online.”
asserted
we → impact → ncsc.gov.uk