ASOS ‘hack’ alert live: Latest from security experts as customers receive threatening messages
The attackers didn’t just rob ASOS. They used ASOS’s own voice to tell their customers. That’s not just a data breach. That’s a complete loss of operational control, and the reputational damage from that alone is significant.
Muhammad Yahya Patel, vCISO and Cybersecurity Advisor at Huntress
Now is not the time for Asos customers to panic because very little is known about the severity of the reported data breach. It is best to never open notifications from retailers in text messages or emails and never click on any of the links received. Customers should go directly to the Asos website for more information about the breach. For all organizations, this breach is another reminder of the importance of adopting a breach mentality because incidents will inevitably occur and no company is immune from being attacked. In general, companies that prepare before incidents improve their chances of minimizing disruptions to their businesses. Furthermore, paying ransoms is not worth it because it not only further fuels the ransomware economy, but it does not guarantee that the threat group will hand over the decryption keys upon payment. Maintaining solid backups and scheduling regular tabletop exercises is extremely important. Organizations should also have a crisis response plan available to activate during cyber incidents that ties into the regular scheduling of tabletop exercises, so that stakeholders are familiar with the initial steps and actions to implement when an incident is discovered.
Jeff Wichman, Senior Director of Breach Preparedness and Response at Semperis
Snowflake is an artificial intelligence and data analytics platform used by several organizations. In 2024, ShinyHunters hacked Snowflake instances from over 160 organizations and stole sensitive data that was used for extortion. They used credentials obtained from data thieves for initial access. This recent hack may be similar, although it is not confirmed what the initial access was. Snowflake has published more than 20 vulnerabilities in its products in 2026, including three considered high criticality in September, but none of them are known to have been exploited by threat actors. The threat actors provided a link to a Telegram channel created today that already has more than 150 subscribers. That channel is then linked to a group chat with over 260 participants. “Xuanye” is not a known threat actor, but the name is of Chinese origin, which could indicate a Chinese-speaking threat actor or simply a false flag.
Daniel dos Santos, vice president of research at Forescout
Snowflake is a huge cloud database where retailers often store sensitive customer information, a real concern if cybercriminals have actually accessed it as they claim. The push notification suggests that the attackers have also breached the systems that control the ASOS mobile app. This is clear public extortion. Sending a ransom demand directly to consumers’ devices is an aggressive extortion tactic designed to force the company into a quick negotiation. I strongly recommend buyers be on the lookout for targeted phishing attempts while we wait for official confirmation of a data breach.
Dray Agha, Senior Security Operations Manager at Huntress
It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed picture of the customer, from their browsing and purchasing habits to their location and loyalty status. This is valuable profile data, although the connection alone does not establish what attackers could access.
Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes
What should you do?
Did you get the ASOS ‘hack’ notification? If so, there are some important things you should not do, including clicking on the Telegram link in the message. You should also:
- Avoid clicking on links in any suspicious emails
- Do not click on links in any suspicious text or messages
Other cybercriminals could try to take advantage of the hysteria caused by the ASOS notification, so you should be especially careful with emails telling you that your account has been compromised or asking you to reset your password.
It is also advisable to be careful when purchasing from ASOS until the company publicly comments on the issue, which has not happened yet.
What did the alert say?
Did anyone else get the ASOS hack notification? Any ideas? https://t.co/WZkWta5dekOctober 6, 2026
ASOS customers first reported receiving the above push alert on Tuesday morning around 4:55am ET / 9:55am BST.
This coincided with an increase in reports about Downdetector. The message is addressed to ASOS’ Data Protection Officer (DPO) and IT team, but was sent to customers.
The ‘snowflake’ the message refers to is software as a service (SaaS) that organizations use as a dedicated cloud environment to store, process and analyze data. This is what has security experts concerned, although it is a little early to say whether customer data has been compromised.



Post Comment