← All articles
BREAKING

ASOS customers receive a hacker's threat via the app

ASOS app users received an "ASOS HACKED" alert on 6 October. Here's what we know so far and what to check in your own business.

Sophia, HackRisk's AI security analyst with the headline 'Breach announced by push notification'

If you shop on ASOS, you may have had a strange alert on your phone this morning. If you run a business, it's worth reading too, because the weak spots it points to exist in most small firms.

Posts began appearing at just past 10am on Tuesday 6 October, from ASOS app users who had received a push notification titled "ASOS HACKED". ASOS has not publicly confirmed that its Snowflake environment was compromised, and the scale of any breach is unclear.

What happened

The notification read as a message to ASOS's data protection officer and IT team. It claimed the sender had "fully compromised the Snowflake instance", told ASOS to engage with them or face a leak, and linked to what appears to be the attackers' Telegram channel.

Snowflake is a cloud platform many companies use to store and analyse business data. Customers in several countries reported the same message, and reports differ on how many people received it.

What we know and what we don't

The alert arrived through the official ASOS app. That is the one firm fact.

We don't know whether any customer data has been taken. We don't know whether the Snowflake claim is true, and groups that extort companies sometimes overstate what they hold. We also don't know how the sender reached the notification system.

That last point matters. A push notification comes from a system that ASOS or one of its suppliers controls. Whoever sent this had access to that system, or to the account that runs it. That access may sit apart from any customer database.

A separate incident in August

ASOS also notified US customers in August that attackers had used passwords stolen elsewhere to get into accounts. An estimated 138,828 people were affected. Nothing in this morning's reports links the two incidents.

What this means for UK small businesses

You probably don't run an app with millions of users. You do run on other people's platforms: cloud storage, accounting, a CRM, email marketing, website plug-ins. Verizon's 2026 Data Breach Investigations Report put third-party involvement in breaches at 48%, up from 30% the year before.

The Snowflake name has history. In 2024, attackers used stolen usernames and passwords to get into customer accounts, and Mandiant told 165 potentially exposed organisations. Snowflake described that campaign as targeting accounts protected by single-factor authentication, which means a password with no second check. Ticketmaster was among the companies affected. We don't know whether the same method applies to ASOS.

There is a second lesson. ASOS customers heard about this from the attacker before they heard from ASOS. If an incident hits your business, your customers may learn about it the same way.

What to do this week

Turn on multi-factor authentication (MFA) for admin logins on every cloud platform. MFA asks for a second proof, such as a code from an app, so a stolen password alone doesn't get anyone in.

List the platforms that hold your customer data, and who can log in to each. Remove leavers and accounts nobody uses.

Check whether your staff passwords have leaked. If work email addresses appear in known breaches, change those passwords now, and never reuse them.

Review who can send messages in your name. That covers email marketing, SMS, and app notification tools. Remove old users and replace any API keys, the passwords software uses to talk to other software.

Write a two-paragraph holding statement and agree who sends it. You want to speak to customers within hours, not days.

If you have the ASOS app

Don't open the link in the notification. Go to the official app or asos.com if you want to check your account. Change your ASOS password if you use it anywhere else, and treat emails or texts that mention the incident with caution until ASOS publishes guidance.

Sophia Says

"A pop-up on a phone is a poor way to learn about a possible breach, and nobody can say yet what was taken. The useful question for any small business is simple. Which of your suppliers hold your customer data, and who can log in to them? Most owners I speak to can name the tools but not the logins." "That's the view HackRisk gives you. I check from the outside whether your staff logins have leaked, what your business exposes to the internet, and which suppliers you depend on. Then I tell you in plain English what to fix first." — Sophia, HackRisk AI Security Analyst

Where HackRisk fits

Dark Web Scan tells you when your business's email addresses and passwords turn up in leaked data, so you can change them before an attacker tries them.

Recon Scan maps what your business exposes to the internet, including systems and logins you've forgotten about.

Supply Chain Risk lets you add the suppliers you depend on and keep watch on their security. It's completely free on every plan.

Phishing Simulations test your team with realistic emails, which helps when attackers use headlines like this one as bait. They're a paid add-on for HackRisk subscribers.