What can I do to protect myself after 'Asos hacked' message?
Asos says people should not engage with the unauthorised notification and says it'll provide further information.
REALNEWS HUB Newsroom
Oct 7, 2026, 06:57 UTC

Online fashion giant Asos has warned customers to ignore an unauthorised alert sent to mobile app users following an apparent extortion attempt by cyber criminals.
Shoppers across the UK received unusual push notifications on Tuesday morning containing a link to a Telegram account. The pop-up, addressed to the company's data protection officer and technology team, claimed that external systems had been compromised and threatened to release data unless the retailer engaged with the perpetrators.
Asos issued an apology for the rogue message, urging recipients not to click the external link. The company stated that it acted swiftly to curb the unauthorized access and is coordinating with external advisers and regulatory bodies to handle the breach.
While the exact extent of accessed records remains under investigation, the retailer notified customers that basic personal records, such as names and contact information, might be involved. However, Asos emphasized that it does not believe passwords or payment card details were compromised. The business also assured shoppers that its website and app continue to run normally.
Data storage provider Snowflake, which was specifically named in the rogue notification, told the BBC that an internal review discovered no evidence that its own infrastructure had been compromised.
Security specialists point out that seeing the notification does not indicate that a user's mobile device itself has been infiltrated. Nevertheless, consumers are being urged to take proactive security measures. Experts advise changing account passwords, especially if the credentials are shared across other platforms, and implementing two-step verification across sensitive services such as personal email and online banking. Customers should also keep track of recent financial statements for unusual charges.
Industry analysts warn that the immediate aftermath of such incidents often brings secondary threats. Cyber criminals frequently exploit confusion by orchestrating phishing attempts, sending fraudulent messages that offer refunds, or directing victims to fake password-reset portals.
Consumer advocates recommend that shoppers treat any unprompted contact claiming to represent Asos with extreme caution. Anyone receiving suspicious telephone calls should disconnect immediately and reach out to the retailer directly using confirmed, official communication channels.
Many details regarding the incident remain unconfirmed, including the identities behind the attack and the overall volume of customers who saw the alert. Asos has pledged to share additional details once its investigation uncovers verified findings.
Source & verification
VerifiedReported from Business.
Get breaking news alerts and the Morning Briefing
Verified stories in your inbox, every one linked to its sources. All newsletters →

