Asos is ‘hacked’ after customers receive message threatening to leak their data

Asos appears to have been hacked after customers received an ‘unusually brazen’ message threatening to leak their data.
The phone alert was sent on the online fast-fashion retailer’s app today, titled ‘ASOS hacked’, and read: ‘Dear ASOS DPO and IT, we have full compromised the Snowflake instance. Engage with us, or we will leak it: t.me/xuanyewengateway.’
DPO refers to the data protection officer in charge of safeguarding customers’ information.
Snowflake is a cloud platform that is used to store, process and analyse data. It also collects customers’ behavioural, transactional and demographic data.
The message also included a link to the hackers’ Telegram channel, the Xuanye group gateway, which was only created today.
Cybersecurity experts said the hackers had started a psychological warfare by sending the ‘unusually brazen’ notification that was ‘designed to whip up panic’.
The Daily Mail has contacted Asos for comment.
Asos, which also owns brands including Topshop and Miss Selfridge, says it has 17 million customers in 150 countries. Its website and app appear to be working still despite the apparent breach.
The firm’s shares plummeted by 11 per cent after reports of the hacking emerged.
Panicked customers have been reacting online to the ‘crazy notification’, and some said they have ‘never deleted my payment methods so quick’.
Asos appears to have been hacked after customers received a message threatening to leak their data
Asos says it has 17 million customers in 150 countries. Its website and app appear to be working still despite the apparent breach
Marie Wilcox, VP of market strategy at cybersecurity firm Binalyze, said: ‘This notification was psychological warfare, designed to whip up panic. Attackers know that any panic piles on the pressure on Asos to think about paying up rather than taking time to develop a rational response.’
Marijus Briedis, chief technology officer at NordVPN, said it was ‘an unusually brazen and threatening message’.
He said: ‘The attackers aren’t simply claiming to have breached Asos – they’re publicly telling the company to engage with them or they will leak what they say they have obtained.’
Mr Briedis said if the claims made by the hackers are genuine, ‘the critical question will be what information was held there and whether any of it was accessed or downloaded’.
‘At this stage, however, customers shouldn’t assume their personal or payment information has been stolen – that hasn’t been established,’ he said.
‘What customers should be particularly alert to now is what happens next. High-profile cyber incidents create ideal conditions for phishing attacks.
‘Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund.’
He added: ‘But this incident shows how powerful access to a trusted communications channel can be. When an attacker can potentially speak to customers through a company’s own systems, it makes the threat considerably more convincing and potentially much more damaging.’
Dr Pete Membrey, the chief research officer at ExpressVPN, said the worst thing people can do is panic.
‘Getting a message like that from an app you trust is genuinely unsettling,’ he said.
‘Most people think of a hack as something that happens out of sight, so seeing a threat land on your own phone makes it feel much more personal.’
Dr Membrey advised Asos customers to do ‘some simple due diligence. Don’t tap on the notification or follow the link in it. Go to the ASOS website directly, by typing in the address yourself rather than through an email or the app, and reset your password’.
Kamran Bahdur, chief information officer at cybersecurity firm FLR Spectron, advised Asos customers to change their passwords ‘for an extra layer of protection and peace of mind’.
He said: ‘This should be taken seriously and treated as a potential extortion attempt until we’ve verified the facts.’
Cyber security expert Jake Moore described it as ‘one of the most visible hacks in history’ and could ‘put a lot of customer data at risk’.
‘By broadcasting their breach directly to Asos app users, the threat actors are likely trying to apply pressure to Asos, showing how extensive their access is so they can leverage some sort of ransom,’ the global cyber security adviser at ESET told the Independent.
He said the fact hackers had sent the message through Asos’ app suggests they had gained access to some of the firm’s systems.
But Mr Moore said it doesn’t ‘prove their full claims about the extent of the data breach’.
Charlotte Wilson, head of enterprise at cyber-security firm Check Point, told the BBC: ‘If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note.’
Britain is Asos’ largest market, representing 49 per cent of all revenues in the first half of the latest financial year.
The fast-fashion firm is undergoing a major turnaround programme to halt declining sales and return to profit.
Mike Ashley’s Frasers Group owns 29.26 per cent of Asos and is the firm’s largest shareholder.
Britain has been hit by several cyber attacks in recent months. In August, up to 1,000 charities, including Breast Cancer UK, English National Ballet and the Molly Rose Foundation, were targeted.
Criminals targeted Beacon CRM, which provides customer management software to the charity sector.
It is thought the firm mistakenly published an access key online that allowed hackers to copy its databases.
Meanwhile, M&S and Co-op were left crippled by a cyberattack in the spring and summer of 2025.
Notorious hacker group Scattered Spider was linked to the attack that left shelves empty for weeks and forced M&S to stop accepting all online orders and payments.
Have YOU been affected? Email matt.strudwick@dailymail.co.uk
