Skip to content

ASOS hacked in data breach affecting UK and Australia

ASOS hacked after customer data breach in the UK and Australia

ASOS is investigating unauthorised activity after customers in the UK and Australia received a threatening push notification claiming hackers had compromised the retailer’s Snowflake environment.

The message was addressed to ASOS’s data protection officer and IT team. Its authors claimed full access to the company’s Snowflake instance and threatened to leak information unless ASOS contacted them through a linked Telegram channel.

ASOS said early Wednesday it was investigating the incident and believed basic personal information, including customer names and contact details, may have been accessed. The online fashion retailer said it had no indication payment-card information or account passwords were affected.

The company serves about 17 mn customers across more than 150 markets. ASOS hasn’t disclosed how many customer records were involved in the incident.

Customers began posting screenshots of the notification shortly after it appeared. Several said they initially mistook it for a promotional message before noticing the wording, while others reported changing passwords or deleting stored payment details.

The Telegram account linked from the notification directed users to another channel created the same day. BBC Verify reported the account names used spellings consistent with Chinese pinyin and some posts appeared translated from Chinese. Those characteristics don’t establish who operated the accounts or where the people behind them were located.

One message on the channel claimed payment information was unaffected and said the incident involved customer information. Those statements haven’t been independently confirmed.

ASOS shares fell 9.56% in London trading as investors reacted to the incident. Despite the decline, the shares remained worth more than twice their level at the start of the year.

The cyber incident arrives as large retailers continue dealing with attacks against customer databases and internal systems. JD Sports, Ticketmaster, Marks & Spencer, Co-op, Harrods, Adidas and several luxury brands have reported major security incidents or customer-data theft since 2023.

For now, ASOS continues operating its website and app while investigating the extent of the access. The company has confirmed possible exposure of names and contact details, while the hackers’ broader claim of compromising its Snowflake environment remains unverified.