Asos says ‘unauthorised party’ impersonated contact to gain log-in details

Read the original at Evening Standard ↗
Evening Standard · collected 2026-10-08 · by Henry Saker-Clark

Quick Summary

Asos announced that an unauthorized party impersonated a trusted contact to gain access to employee log-in details, resulting in some customer personal and non-personal account-related information being accessed on third-party platforms used by Asos. The company stated that no payment card information or account passwords were compromised and urged customers to be cautious of unsolicited messages or calls claiming to be from the retailer. Asos also reported that they have taken steps to enhance their security measures following this incident.
Written locally by qwen2.5:14b on 2026-10-08, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

On Tuesday morning, ASOS customers received a phone alert claiming the retailer had been hacked. The message included a link to a Telegram chat threatening to leak customer data unless ASOS engaged with the hackers. Snowflake, an online platform used for storing and analyzing large amounts of data, was cited as being compromised by the alleged attackers.

More than 400 customers reported issues on Downdetector, and ASOS's shares fell almost 12% on the London Stock Exchange. The company acknowledged the issue but stated that it did not believe payment card information or account passwords were impacted, though personal data such as names and contact details may have been accessed.

ASOS has 17 million customers in over 150 countries, with the UK being its largest market at 49% of revenues. The company is currently undergoing a major turnaround program to halt declining sales and return to profit. Previous high-profile retail hacks include those on Marks & Spencer and Harrods.

Cyber experts warn that these incidents create ideal conditions for phishing attacks, urging customers to be wary of potential follow-up communications from ASOS or any other suspicious emails or texts.

Written for “Asos Data Breach” on 2026-10-08, grounded in this article and the 15 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
14
claim-shaped sentences
Uncertain
0%
0 of 14 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
66.0
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
16
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-10-08 · how these are computed

Story

📰 Asos Data Breach
Technology · 16 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 0% of its claims. Each row says how that neighbour differs.
Evening Standard
⚖️ leaning not scored 🔴 20% hedged 3 of 15 📰 publisher trust 66
“Both articles describe the same incident where Asos customers received alerts about a hack, and subsequent statements from Asos regarding an unauthorized party gaining access to employee log-in credentials through impersonation.”
Evening Standard · 0.88 cosine similarity
⚖️ leaning not scored 🔴 5% hedged 1 of 19 📰 publisher trust 66
“Both articles describe the unauthorized access incident at Asos, involving customer data potentially being accessed and an impersonation attempt to obtain login details.”
Evening Standard · 0.88 cosine similarity
⚖️ leaning not scored 🔴 14% hedged 3 of 22 📰 publisher trust 66
“Both articles describe Asos responding to unauthorized activity and warning customers about potential impersonation, referencing the same time frame and nature of the incident.”
Evening Standard · 0.86 cosine similarity
⚖️ leaning not scored 🔴 25% hedged 1 of 4 📰 publisher trust 66
“Both articles discuss the same cybersecurity incident at Asos involving unauthorized access and customer alerts, with similar timing.”
Evening Standard
⚖️ leaning not scored 🔴 9% hedged 1 of 11 📰 publisher trust 66
“Both articles discuss ASOS customers receiving alerts about potential hacking and ASOS's subsequent statement about unauthorized access through impersonation.”
Evening Standard
⚖️ leaning not scored 🔴 0% hedged 0 of 7 📰 publisher trust 66
“Both articles refer to the same security incident involving Asos customers receiving phone alerts about a hack, and Asos's subsequent statement clarifying that an unauthorized party gained access through impersonation.”
The Guardian
⚖️ leaning not scored 🔴 20% hedged 3 of 15 📰 publisher trust 68
“Both articles describe customers receiving notifications about a potential hack on Asos, and subsequent actions by Asos to investigate and inform customers.”
ABC News (AU)
⚖️ leaning not scored 🔴 0% hedged 0 of 4 📰 publisher trust 61
“Both articles refer to the same incident where Asos app users received messages claiming a hack, and subsequent updates from Asos about an unauthorized party gaining access through impersonation.”
Evening Standard
⚖️ leaning not scored 🔴 18% hedged 3 of 17 📰 publisher trust 66
“Both articles discuss the same security incident involving Asos customers receiving alerts about a hack, and provide details from official statements by Asos regarding an unauthorized party gaining access.”
The Straits Times
⚖️ leaning not scored 🔴 13% hedged 3 of 23 📰 publisher trust 59
“Both articles describe Asos investigating unauthorized activity following customer alerts of a potential hack, with Article B providing more details about an impersonation attack to gain log-in credentials.”

Publisher

Evening Standard · 4140 article(s) · 35 correction(s) detected
Running correction rate · 35 correction(s)
2026-10-08
Tottenham injury update: Latest return dates before Manchester United after new double scare
2026-10-08
Manchester City injury update: Erling Haaland, Nico O'Reilly and Antoine Semenyo latest news and return dates
2026-10-08
Manchester United injury update: Kobbie Mainoo, Marcus Rashford, Benjamin Sesko latest news and return dates
2026-10-08
Arsenal injury update: Ezri Konsa, Christos Tzolis, Kai Havertz latest news and return dates (cloned)
2026-10-08
Chelsea injury update: Cole Palmer, Moises Caicedo, Joao Pedro latest news and return dates
2026-10-08
Liverpool injury update: Alexander Isak, Cody Gakpo, Jeremy Jacquet latest news and return dates
2026-10-06
Arsenal injury update: Ezri Konsa, Christos Tzolis, Kai Havertz latest news and return dates
2026-10-06
Chelsea injury update: Moises Caicedo, Joao Pedro, Cole Palmer latest news and return dates
2026-10-05
Liverpool injury update: Alexander Isak, Cody Gakpo, Hugo Ekitike latest news and return dates
2026-10-05
Manchester United injury update: Marcus Rashford, Benjamin Sesko, Kobbie Mainoo latest news and return dates
2026-10-05
Tottenham injury update: Micky van de Ven, Jan Paul van Hecke, Pedro Porro latest news and return dates
2026-10-05
Arsenal injury update: Christos Tzolis, Kai Havertz, Declan Rice latest news and return dates
2026-10-05
Chelsea injury update: Joao Pedro, Cole Palmer, Moises Caicedo latest news and return dates
2026-10-02
Arsenal injury update: Christos Tzolis, Declan Rice, Kai Havertz latest news and return dates
2026-10-01
Manchester United injury update: Bruno Fernandes, Marcus Rashford, Kobbie Mainoo latest news and return dates
2026-09-28
Arsenal injury update: Martin Odegaard, Declan Rice, Kai Havertz latest news and return dates
2026-09-28
Arsenal injury update: Kai Havertz, Declan Rice and Piero Hincapie latest news and return dates
2026-09-28
Manchester United injury update: Bruno Fernandes, Marcus Rashford, Kobbie Mainoo latest news and return dates
2026-09-28
Liverpool injury update: Alexander Isak, Cody Gakpo and Hugo Ekitike latest news and return dates
2026-09-27
Chelsea injury update: Cole Palmer, Joao Pedro, Reece James latest news and return dates
2026-09-24
Arsenal injury update: Ben White, Cristhian Mosquera, William Saliba latest news and return dates
2026-09-24
Chelsea injury update: Joao Pedro, Cole Palmer, Reece James latest news and return dates
2026-09-21
Chelsea injury update: Joao Pedro, Reece James, Moises Caicedo latest news and return dates
2026-09-21
Arsenal injury update: Ben White, Cristhian Mosquera and William Saliba latest news and return dates
2026-09-21
Tottenham injury update: Pedro Porro, Dejan Kulusevski and Mykhailo Mudryk latest news and return dates
2026-09-21
Manchester United injury update: Benjamin Sesko, Carlos Baleba, Amad Diallo latest news and return dates
2026-09-21
Liverpool injury update: Hugo Ekitike, Conor Bradley, Federico Chiesa latest news and return dates
2026-09-17
Tottenham injury update: Sandro Tonali, Pedro Porro, Dejan Kulusevski latest news and return dates
2026-09-17
Liverpool injury update: Hugo Ekitike, Federico Chiesa and Giovanni Leoni latest news and return dates
2026-09-17
Man Utd injury update: Luke Shaw, Amad Diallo, Carlos Baleba latest news and return dates
2026-09-17
Arsenal injury update: Jurrien Timber, Ben White, Cristhian Mosquera latest news and potential return dates
2026-09-17
Chelsea injury update: Joao Pedro, Moises Caicedo and Marco Palestra latest news and return dates
2026-09-16
Chelsea injury update: Joao Pedro, Reece James, Moises Caicedo latest news and return dates
2026-09-11
Liverpool injury update: Bradley Barcola, Cody Gakpo, Milos Kerkez latest news and return dates
2026-09-10
Chelsea injury update: Levi Colwill, Moises Caicedo and Marco Palestra latest updates and return dates

Who wrote this

Henry Saker-Clark
57 article(s) here · 1 carrying a prediction
🔮 The regulator would have fined Deloitte £11 million but reduced this to £6.05 million because of co-operation and admissions by the firm.
2026-10-08 · assertive framing · Deloitte fined £6m by watchdog over Go-Ahead audits
🔮 “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
🔮 Boots to be bought by Canada’s Weston family for £6.7bn Wittington Investments, the Weston’s holding company, will buy the business from majority owner, private equity firm Sycamore Partners, and the Pessina family.
🔮 The £14.9 million deal will see Likewise buy Headlam’s Thatcham distribution centre, including operating assets and inventory on sites, the trade and assets of its Crucial Trading business, and trade and assets for Concept Flooring in West Bromwich and Stoke-on-Trent.
🔮 The online retailer, which has 16.5 million customers, said personal informational, such as names and contact details, “may have been accessed” as a result.
🔮 The fashion giant, which has 16.5 million customers, said personal informational, such as names and contact details, “may have been accessed” as a result.
🔮 The fashion giant, which has 16.5 million customers, said personal informational, such as names and contact details, “may have been accessed” as a result.
🔮 “The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.
🔮 “The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.
🔮 In the accounts, the company said it will pay its parent company, Jelly Holdings, around £179 million in dividends for the 2025 financial year, but it is understood this will stay in the group for reinvestment.
Also by Henry Saker-Clark
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 57 articles by Henry Saker-Clark →

Topics

Asos Snowflake

Subjects

Asos ORG · 10× Snowflake ORG · 2×

Narrative

Asos said it has undertaken a detailed investigation over the past 48 hours and found an “unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials”.
framing: assertive · carried by 1 article(s) · first seen 2026-10-08
🔮 “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”
2026-10-08 · Evening Standard
Asos says ‘unauthorised party’ impersonated contact to gain log-in details · assertive framing

Claims (14 extracted, 0 hedged)

Asos has said an “unauthorised party” gained access by impersonating a trusted contact to get log-in information, after customers received a phone alert saying that the retailer had been hacked. asserted
retailer → say → alert
The fast fashion business told customers to “remain cautious” over unexpected messages or calls claiming to be from Asos, in an email on Thursday morning. asserted
business → tell → morning
Asos said it has undertaken a detailed investigation over the past 48 hours and found an “unauthorised party gained access to an Asos employee account by impersonating a trusted contact to obtain log-in credentials”. asserted
party → say → credentials
It said the party then used the credentials to access information on third-party platforms used by Asos. asserted
party → say → Asos
Affected platforms were immediately locked down but Asos said the attacker gained access to some personal data, including names and contact details. asserted
attacker → lock → names
The also were able to access “certain non-personal account-related information”, Asos said. asserted
Asos → access → information
But it stressed that no payment card information or account passwords were accessed. asserted
information → stress → ?
The Asos website and app were safe to use throughout the incident and “remain safe” to use, the firm said. asserted
firm → use → incident
However, the company urged customers to remain vigilant. asserted
company → urge → customers
It said: “There is no action you need to take on your account. asserted
you → say → account
“We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.” asserted
We → ask → message
Asos added that it has already taken steps to strengthen its security controls and will continue with its full investigation. asserted
it → add → investigation
The notification message sent out by cyber attackers referred to cloud firm Snowflake, which stores data for many major companies. asserted
which → send → companies
Snowflake said it has “found no compromise” of its platform after launching an investigation following the notification message. asserted
it → say → message
💬Give feedback
🕘History 🎫Support