ASOS users issued warning as app ‘hacked’ and threatening message appears
ASOS users received a threatening message from ‘hackers’ (Getty Images)
ASOS is investigating after customers received a threatening push notification through the retailer’s app claiming its data had been “fully compromised” and warning that the sender demanded engagement or they would leak it, alongside a Telegram link.
The notification, titled “ASOS hacked”, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” The message was apparently written by whoever sent the alert. DPO is a reference to a company’s data protection officer, and Snowflake is a cloud data platform used to store, process and analyse data.
The website and app appeared to remain operational on Tuesday morning (6 October), despite the alert. It is not confirmed that customer personal or payment information has been stolen.
ASOS later said in a statement that an “unauthorised customer notification” was sent to users at around 10am.
Their statement added: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.”
It continued: “Basic personal information including name and contact details may have been accessed. We do not believe that payment-card information or account passwords were impacted.”
The company said “customer trust is incredibly important” and updates will be provided as needed.
What should ASOS customers do if they got the notification?
Cyber security adviser Jake Moore, global cyber security adviser at ESET, urged people not to click through. “This has got to be one of the most visible hacks in history,” he said on X.
Marijus Briedis, chief technology officer at NordVPN, warned customers to be on the lookout for phishing attempts that can follow high-profile cyber incidents, and to avoid clicking links in unexpected messages even if they look convincing, as per The Guardian.

Dray Agha, senior manager of security operations at Huntress, described the tactic as “clear public extortion”, adding: “Sending a ransom demand directly to consumer devices is an aggressive extortion tactic designed to force the business into a quick negotiation.”
Shoppers left scared
ASOS says it has 17million customers each year in more than 150 countries, underlining how widely a message like this could spread if it reached a large chunk of its user base.
The market reaction was swift, with ASOS shares falling by an estimated 10 to 12% on Tuesday morning after the notification, wiping about £70million off the company’s value in one account.
Users quickly reacted online. One said on X: “ASOS getting hacked oh let’s all just pack up and leave.” While others were thankful they had no payment methods saved on the site.
Share your thoughts! Let us know in the comments below, and remember to keep the conversation respectful.