The Wire
BusinessTechnologyLaw & RegulationCybersecurity

ASOS investigates possible customer-data access after rogue push alert

ASOS investigates possible customer-data access after rogue push alert
Photo: theguardian.com

ASOS is investigating possible data access after an unauthorised customer push notification.

Why it matters: ASOS faces an investigation, incident-response work, possible customer notification and potential scrutiny from the Information Commissioner's Office. The incident also raises questions about third-party communications systems connected to consumer platforms.

  • An unauthorised notification titled "ASOS HACKED" reached customers at about 10 a.m. on October 6, 2025.
  • ASOS said basic information, including names and contact details, may have been accessed; payment-card information and account passwords were not believed to be impacted.
  • ASOS has 19.6 million active customers, while its shares fell roughly 10% to 11% during trading, according to reports.
  • The UK's National Cyber Security Centre advised ASOS customers to assume they were affected and watch for suspicious communications.

ASOS said an unauthorised party used third-party platforms involved in customer communications to send a push notification through its app on October 6, 2025. The message claimed attackers had "fully compromised the Snowflake instance" and directed recipients to Telegram. ASOS said it immediately restricted access to the notification platforms and brought in internal and external specialists and relevant authorities.

The confirmed event is unauthorised use of a communications system. That push notification does not by itself establish access to customer data. ASOS said basic personal information, including names and contact details, may have been accessed, but has not said that data was exfiltrated. It added: "We do not believe that payment-card information or account passwords were impacted." The website and app continued to operate normally.

The claim about Snowflake remains unverified. A Snowflake spokesperson said the company had found no compromise of its platform at the time of the statement. ASOS has not named the third-party communications provider involved, said how many customers received the notification or confirmed any data exfiltration.

The National Cyber Security Centre advised ASOS customers to assume they were affected, including those who did not receive the message. That was precautionary guidance, not confirmation that every customer's data had been exposed. Customers were told to watch for suspicious communications.

ASOS must assess whether the incident qualifies as a notifiable personal-data breach. ICO guidance says the 72-hour period runs from awareness of a qualifying breach, and notification is required without undue delay, where feasible within 72 hours, when the breach is likely to pose a risk to individuals' rights and freedoms. The ICO says organisations must assess that risk; notification is not automatically required for every security incident.

ASOS shares fell roughly 10% to 11% during trading, according to the Euronext report. The price move and trading timing do not, on their own, establish that investors were reacting to the incident.

By the numbers

  • 19.6 million - ASOS active customers
  • 10%-11% - reported share-price decline during trading
  • 72 hours - the feasible notification window after awareness of a qualifying, risk-bearing personal-data breach

Yes, but: ASOS has confirmed unauthorised use of a customer-communications system and possible access to basic personal information, but it has not confirmed customer-data exfiltration or a compromise of Snowflake.

What's next: ASOS is investigating with internal and external specialists and relevant authorities. It must assess whether the incident meets the ICO's threshold for notification and, if so, notify without undue delay and where feasible within 72 hours of awareness.

Based on reporting from

  • The Guardian

See how this story touches your network - open The Wire in Jane.

Open in Jane