ASOS investigates data breach after fake customer message
The British online retailer says names and contact details may have been viewed, but for now sees no indication that passwords or payment-card details were affected.
ASOS is investigating a cyber incident in which customers received an unauthorised message. The company says basic details may have been obtained; the website and app are operating normally for now.
ASOS reported on 6 October that an unauthorised message had been sent to customers at around 10.00am. The company says the message was linked to unauthorised activity on third-party platforms used to communicate with customers.
The company is investigating exactly what happened with internal and external experts. Relevant authorities have also been informed, ASOS said. The company restricted access to the messaging platforms involved after the incident was discovered.
According to the statement, basic details such as names and contact details may have been viewed. ASOS says it has no indication that payment-card details or passwords were affected by the incident. This is a preliminary assessment; the investigation into the extent of the access is still under way.
The message caused concern among users because its wording appeared to come from attackers and referred to an alleged intrusion into a Snowflake environment. Snowflake denied to ITPro that the claim had been confirmed by this. ASOS has not publicly established exactly which systems were infiltrated.
The online retailer says its operations have not been disrupted. Customers can continue to use the website and app, but should remain alert to new messages asking for login details, payments or other personal information. The incident does not mean that every customer was actually affected.
ASOS has cyber insurance and says it is still too early to calculate the financial consequences. That statement says nothing about any obligations towards customers or regulators. Under UK privacy law, companies may be required to inform affected individuals when a data breach poses a high risk to them.
For now, the main clear point is that communication infrastructure operated by or on behalf of ASOS was misused and that some customer data may have been accessible. It is not yet clear how many customers were affected, whether the attackers copied data, or whether additional systems were involved in the incident.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical and business facts were checked directly against ASOS’s statement and independent reporting. Unconfirmed claims about the attack have been described as unconfirmed.
- confirmed ASOS sent an unauthorised customer message on 6 October. — This is stated in ASOS’s official RNS announcement. source
- confirmed Names and contact details may have been viewed. — ASOS explicitly identifies these as potentially affected basic details. source
- confirmed ASOS has no indication that payment-card details or passwords were affected. — This is ASOS’s preliminary assessment, not a definitive forensic conclusion. source
Editor's note
ASOS confirms possible access to names and contact details, but not that payment details or passwords were affected. The extent of the incident and the authenticity of the Snowflake claim have not yet been established.Sources
- Update regarding cyber incident — ASOS plc via London Stock Exchange RNS
- Asos says customers' personal information may have been accessed — BBC News
- Asos users report concerns after receiving push notification from cyber criminals — ITPro
More on this in Dutch media
- de Volkskrant — „asos datalek”
- NOS — „asos datalek”
- Het Parool — „asos datalek”