ASOS investigates report of possible data breach
Users received a threatening push notification, but the company has not publicly confirmed a hack or stolen customer data.
Thousands of users of the ASOS app received a push notification on Tuesday reading ‘ASOS HACKED’. It claimed that a Snowflake environment had been taken over and that data could be leaked, but independent confirmation of a data breach is so far lacking.
STV News writes that the notification was addressed to ASOS’s IT department and data protection officer. According to the British broadcaster, the sender threatened to publish data if ASOS did not make contact. The notification appeared in the app and was therefore visible as a message from the platform itself.
That does not prove that the attackers had access to ASOS’s systems. It could also involve the misuse of an account or service used to send push notifications. The public information does not make clear which environment was affected, whether data was accessed or how many customers might be involved.
The notification mentions Snowflake, a cloud platform for data storage and analysis. STV points out that Snowflake customers were targeted in a broader theft and extortion campaign in 2024. That connection in itself says nothing about the cause of the current notification at ASOS.
ASOS explains on its customer service page that customers may receive push notifications about orders, returns and offers, among other things. The company also advises customers to verify contact only through official ASOS channels. However, the page does not confirm that Tuesday’s notification was part of a successful intrusion.
The core of the news is therefore the notification itself, not a proven customer data breach. The public sources consulted contain no substantive confirmation or denial of the claim by ASOS. Until that information is available, it cannot be established whether passwords, payment details or other customer information are at risk.
One story, several perspectives
What is established
- A push notification containing a hacking claim appeared to users.
- The claim of access to customer data has not been confirmed.
- ASOS has published general information about push notifications and official communication channels.
Left
Arguments Platforms must quickly and fully report what has happened to customer data and must not shift risks onto individual users.
Values Privacy, consumer protection and the responsibility of large technology companies.
Consequences Greater transparency and stricter enforcement can limit harm, but may also force companies to share information before the investigation is complete.
Centre
Arguments Companies must inform customers in good time, but should first establish technically whether data was actually accessed.
Values Carefulness, legal certainty and proportionate communication.
Consequences A phased notification process prevents both unnecessary panic and warnings that come too late.
Right
Arguments Companies should bear responsibility for security and recovery themselves; new rules and broad reporting obligations should not automatically become the norm for every false or unsubstantiated notification.
Values Individual responsibility, innovation and limiting administrative burdens.
Consequences Fewer rushed notifications can limit costs, but customers may hear later that their data may have been misused.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved with corrections · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The push notification and its contents were reported by STV, but a successful hack has not been independently confirmed. The text has therefore been explicitly toned down from an established hack to an unconfirmed claim.
- confirmed ASOS app users received a notification reading ‘ASOS HACKED’. — STV News published the notification and described its distribution among users. source
- confirmed The notification claimed that a Snowflake environment had been compromised. — The notification’s full text was reproduced by STV. source
- uncertain ASOS has publicly confirmed a hack or data breach. — STV reported that ASOS had been asked for comment; the ASOS page consulted does not confirm the incident. source
1 correction(s) applied
- Was: ASOS possibly hackedNow: ASOS investigates report of possible data breach (A hack or data breach has not been independently confirmed in the available public sources.)
Editor's note
The push notification was reported by STV and discussed by multiple public users. Official confirmation of a hack, the extent of any access or the customer data involved is lacking; therefore, the status remains insufficient_sources.Sources
More on this in Dutch media
- Het Parool — „asos cyberaanval”
- NRC — „asos cyberaanval”
- Tweakers — „asos cyberaanval”