Online fashion retailer Asos has confirmed that a hacker reached customers’ names, contact details and app search histories after tricking their way into an employee account. Card details and passwords were not taken, but the stolen data is exactly the raw material scammers use, so the main risk now is convincing fake messages.
Key takeaways
- Asos says names, email and delivery addresses, phone numbers and some account information such as recent searches were accessed. It says payment cards and passwords were not.
- The attacker impersonated a trusted contact to get an employee’s login, then used it on third-party platforms Asos uses to message customers.
- The UK’s National Cyber Security Centre advises all Asos customers to assume they are affected and to watch for scam messages, which can arrive long after a breach.
Why everyone is talking about it
The breach announced itself in an unusual way. On Tuesday 6 October, many shoppers opened their phones to a push notification from the Asos app titled “Asos hacked”, addressed to the company’s data protection officer and IT department. According to Reuters, it read: “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” Unsurprisingly, “Asos” became one of the most-searched terms of the week.
Investors reacted too. Asos shares fell about 10% on the day the notification went out, Reuters reported. They recovered 3% on Thursday after the company set out what had been taken, leaving the stock around 8% lower for the week.
The facts so far
- What was accessed: after a 48-hour investigation, Asos told customers on 8 October that names, email and delivery addresses and phone numbers were accessed, plus some other account information, which reports say includes recent app search history. A data sample seen by the BBC also contained customer numbers.
- What was not: Asos says payment card details and account passwords were not affected, and that its website and app were safe to use throughout.
- How it happened: the company said an intruder posed as a trusted contact to obtain an employee’s login, then used those credentials on third-party platforms that hold customer communication data. Those platforms were locked down.
- Who: a group calling itself “Xuanye group” claimed responsibility. Data company Snowflake said it found no compromise of its own platform.
- Still unknown: how many of Asos’s customers are affected. The company says it is working with law enforcement and regulators and has cyber insurance, but that it is too early to put a figure on any impact on trading.
The background
This was not a high-tech break-in through the front door. It was “social engineering”: persuading a person to hand over the keys. Think of a burglar who doesn’t pick the lock but phones the house-sitter pretending to be the owner and asks where the spare key is. Reuters notes that this kind of attack has been behind several damaging incidents at British organisations, including Marks & Spencer, the Co-op and Jaguar Land Rover.
The breach also shows how much modern retailers depend on outside services. Customer data often sits not only in a company’s own systems but in cloud databases and marketing tools run by other firms. Each connection is a door that needs guarding. In 2024, Google’s Mandiant unit reported a hacking spree targeting Snowflake-hosted data linked to at least 165 organisations.
For Asos the timing is awkward. Its shares had risen more than 60% this year as it sold assets and, last month, gave an upbeat profit forecast. They remain far below their 2018 peak.
What it means for your money
No card numbers or passwords means nobody can simply log in or spend on your card using this data. The real danger is phishing: messages that look genuine because they know things about you. A scammer holding your name, address, phone number and recent searches can write a very believable text.
A worked example. Suppose you searched the Asos app for “wide fit boots” last week. A few days later you get a text: “Hi Sam, your Asos order of wide fit boots to 12 High Street couldn’t be delivered. Pay £1.45 redelivery fee here.” But the £1.45 is bait: the link leads to a fake page built to capture your full card details, which can then be used for much larger purchases. Asos says it will never ask for passwords, security codes or payment details through unsolicited messages or calls.
Sensible general steps, in line with NCSC guidance:
- Don’t click links in unexpected texts, emails or push notifications. Open the app or type the website address yourself.
- If you reused your Asos password elsewhere, change it on those sites anyway, and turn on two-step verification or passkeys where offered.
- Check bank and card statements for small, unfamiliar payments, which are often a test before larger fraud.
- If you’re targeted, report it. In the UK, the NCSC points people to the Stop! Think Fraud service.
For shareholders, the question is cost: investigations, customer communications and any regulatory action. Asos has not quantified it yet. This is general information, not financial advice.
What to watch next
- Whether Asos discloses how many customers were affected, and whether the hackers carry out their threat to leak the data.
- Any response from the UK data watchdog, which can investigate and fine firms over data protection failures.
- Asos’s next trading update, for any estimate of the financial hit. We track the wider market reaction in our daily roundups, such as World Economy in 24 Hours, and key company dates on our economic calendar.
Sources
- Reuters via KSL: UK online retailer ASOS shares drop on reports of cybersecurity breach (6 Oct 2026)
- Reuters via Euronext: UK’s ASOS says cyber hack accessed customers’ personal data (8 Oct 2026)
- National Cyber Security Centre: Incident affecting ASOS customers
- TechCrunch: Asos confirms breach of customer data after hackers send rogue app notification
- Irish Examiner: Asos says hacker accessed customers’ search histories along with names and contact details
- Infosecurity Magazine: ASOS confirms data breach linked to stolen employee credentials
Written by The Daily Economy editorial team with AI assistance and checked against the sources above. Read our editorial policy.
