ASOS Data Breach: What Happened and Who's Affected
A hijacked push notification system, a Telegram threat, and an NCSC warning to every ASOS customer: here's what's confirmed so far and what to do now.

ASOS has confirmed it is investigating a cyber incident after attackers hijacked the retailer's in-app push notification system on October 6, 2026, sending unauthorized "ASOS hacked" alerts to customers' phones. ASOS says names and contact details may have been accessed, but it does not believe payment card numbers or account passwords were affected. The UK's National Cyber Security Centre (NCSC) has told all ASOS customers to assume they are affected, even if they never received the rogue notification.
What happened: On the morning of October 6, 2026, ASOS customers began receiving an unauthorized push notification sent through the platforms ASOS uses to message customers. ASOS restricted access to those platforms and is investigating with specialist advisers and UK authorities.
What may have been exposed: Basic personal information — names and contact details.
What ASOS does not believe was affected: Payment card information and account passwords.
Who should act: Every ASOS customer, per NCSC guidance — not just those who saw the notification.
What happened in the ASOS data breach
At around 10am on Tuesday, October 6, 2026, some ASOS customers received a push notification through the ASOS app that they had not asked for and that ASOS had not sent as part of any normal marketing or order-update message. According to the NCSC's advisory, the notification told customers that ASOS had been "hacked" and pointed them toward a Telegram channel.
ASOS confirmed the incident the same day in a regulatory announcement to the London Stock Exchange. In its own words, filed as an RNS statement, ASOS said it was "investigating unauthorised activity involving third-party platforms it uses to communicate with customers," and that it had restricted access to those notification platforms as a containment step while it works with internal and external specialist advisers and relevant authorities. You can read the full ASOS RNS release directly.
That detail matters because it changes who needs to pay attention. A breach of a retailer's core checkout or database would mainly worry people who placed an order recently. A breach of the messaging system a retailer uses to talk to its entire customer base is different: it can reach — and potentially expose data tied to — anyone who has ever created an ASOS account and opted into app notifications or marketing contact, whether or not they've shopped recently. That's also why ASOS reached for the term "unauthorised activity involving third-party platforms" rather than describing a breach of its own servers, and why the NCSC's advice applies so broadly.
Third-party platform compromises like this one have become a recurring pattern across large organizations in 2026 — attackers go after a vendor or service a company relies on to communicate with or store information about its customers, rather than attacking the company's own front door directly, since a single vendor compromise can potentially touch many client organizations at once. The same broad pattern — a breach traced back to a system or vendor relationship rather than a retailer's core platform — has shown up in other recent disclosures, including the incident affecting the Pentagon's DMDC system.
Timeline: how the ASOS breach unfolded
| Date | Event |
|---|---|
| October 6, 2026, ~10am | Unauthorized push notification sent to ASOS customers through third-party messaging platforms; notification references a hack and links to a Telegram channel. |
| October 6, 2026 | ASOS restricts access to the affected notification platforms and files a regulatory ("RNS") announcement confirming it is investigating a cyber incident. |
| October 6, 2026 | UK National Cyber Security Centre publishes a public advisory telling all ASOS customers to assume they are affected. |
| October 8, 2026 | NCSC advisory page shows a last-modified update (specific changes not detailed on the page). |
| October 9, 2026 | ASOS says its website and app continue to operate normally, with no disruption to trading reported; it says it is "too early to quantify any potential impact on trading." |
What data was exposed — and what wasn't
ASOS and the NCSC have been specific about the scope of confirmed exposure so far. The NCSC advisory quotes ASOS saying that "personal information including name and contact details has been accessed," while ASOS's own RNS statement is phrased slightly more cautiously, saying basic personal information, including name and contact details, "may have been accessed." Neither source has published a number of affected customers.
| Exposed / may be exposed | Not believed to be affected |
|---|---|
| Customer names | Payment card numbers |
| Contact details (e.g. email, phone) | Account passwords |
Both ASOS and the NCSC stop short of confirming any specific attacker claims about the scale or method of the intrusion — a distinction worth keeping in mind as unverified claims circulate online (more on that below).
It's also worth being precise about what "accessed" means here. Neither ASOS nor the NCSC has said whether the exposure involves a large historical customer database or a smaller, more recent slice of accounts — a meaningful difference if you're trying to judge your own risk. Until ASOS publishes a fuller forensic update, the only responsible reading of "name and contact details may have been accessed" is the broadest one: treat it as covering any account that has ever interacted with ASOS's messaging systems, not just recent orders.
Who is affected by the ASOS breach
This is the part of the story that catches a lot of ASOS customers off guard: the NCSC explicitly says you should assume you're affected even if you personally never saw the rogue notification. Push notifications are unreliable — they depend on whether you have the app installed, whether notifications are enabled, and whether your phone was online at the right moment — so the absence of a notification on your phone tells you nothing about whether your data was part of the exposure. ASOS has not published a breakdown by region or account type, so the practical guidance from the NCSC is to treat every ASOS account as potentially affected.
That guidance is worth underlining because it runs against a common instinct. Many people only start worrying about a breach after they personally receive some kind of alert — an email, a text, or in this case a push notification. The NCSC's advisory is explicitly designed to head that instinct off: it says plainly that the rogue notification was only sent to "some" customers, and that everyone else should not take silence as a sign of safety. If you have ever had an ASOS account, used the app, or given ASOS your name, email address, or phone number, the sensible default is to assume your basic contact details are part of what may have been accessed, and to act accordingly — even if your phone never buzzed on October 6.
What the attackers are claiming (unverified)
Separately from ASOS's and the NCSC's confirmed statements, a group that identifies itself as "Xuanye Group" has posted claims on a Telegram channel — the same channel the rogue push notification linked to — asserting that it compromised a Snowflake cloud data environment tied to ASOS and threatening to leak customer data. These are the attackers' own claims, made on their own Telegram channel, and neither ASOS nor the NCSC has confirmed the Snowflake angle, the group's identity, or any specific customer count tied to it. Treat any number, screenshot, or sample "proof" circulating from that channel as an unverified claim from the people responsible for the attack, not as a verified fact, until ASOS or a named authority confirms it.
NCSC's advice: what ASOS customers should do now
The NCSC's advisory lays out a short list of recommended actions for anyone who has an ASOS account, regardless of whether they received the fake notification:
- Confirm you're affected. Since notifications are unreliable, assume you are.
- Watch for scams. Phishing attempts can arrive well after a breach is first disclosed, sometimes using the stolen contact details to make messages look more convincing.
- Don't click suspicious links in push notifications, emails, or text messages claiming to be from ASOS — including links that claim to show "proof" of the breach.
- Report fraud through the UK's Stop! Think Fraud service if you believe you've been targeted.
- Use passkeys, or a strong, unique password plus two-step verification on your ASOS account, so a leaked name and email address alone can't be used to take it over.
The NCSC's own data breach guidance for individuals and families and its phishing scams collection go into more detail on each step, including how to spot a convincing fake message. If you haven't set up a passkey before, the NCSC also publishes a short explainer on what passkeys are and why they help.
What ASOS says it's doing
In its RNS filing, ASOS said it had restricted access to the third-party notification platforms involved and is working with "internal and external specialist advisers and relevant authorities" on the investigation. The company said its website and app were "operating normally" with no disruption as of its October 6 statement, and that it would provide a further update "if the situation changes." ASOS also disclosed that it holds cyber security insurance, including business continuity cover, through a large global provider, while cautioning that it's "too early to quantify any potential impact on trading." As of publication, ASOS has not released a customer count or named the third-party platform involved.
How to check if your ASOS account is at risk
There's no ASOS-run lookup tool tied to this specific incident, and per the NCSC's guidance, the safest working assumption is that your account could be affected regardless of what any checker says. A few practical steps:
- Open the ASOS app or site directly (never through a link in a notification, email, or text) and check your account's recent order and login activity for anything unfamiliar.
- Change your ASOS password to a long, unique one you don't reuse anywhere else, and turn on two-step verification if it's offered.
- If your email or phone number was shared across multiple services, watch those accounts too — not just ASOS — since the leaked contact details could be used to target you elsewhere. Our guide on what a password manager does and whether you need one covers how to generate and track unique logins across sites.
- Be skeptical of any message, including ones that look like they're from ASOS, that urges urgent action, asks you to "verify" your account, or links to a page outside asos.com.
How to protect yourself going forward
Breaches like this one are a reminder that the weak point isn't always the retailer's main servers — in this case, the entry point was reportedly the messaging system used to talk to customers, not the ASOS checkout itself. That means the most useful personal defenses are the ones that don't depend on any one company getting its security right: unique passwords (or passkeys) per account, two-step verification wherever it's offered, and a healthy suspicion of any link that arrives via notification, text, or email rather than by typing a web address yourself. Similar advice applied after other recent disclosures, including the breaches affecting the Frontline Education and Arizona Supreme Court systems.
What's next: what to do now
ASOS has said it will update the public "if the situation changes," and the NCSC's advisory page was itself updated on October 8, two days after the initial disclosure, though neither organization has detailed exactly what changed. Until a fuller statement arrives — including, potentially, confirmation or denial of the attackers' Snowflake claim and a customer count — the practical guidance doesn't change: assume your ASOS account could be affected, update your password, turn on two-step verification or switch to a passkey, and treat any ASOS-branded message you didn't expect, including ones referencing this breach, as suspicious until you've verified it by going directly to asos.com or the official app. We'll update this article as ASOS or the NCSC release further details.
Frequently asked questions
What happened in the ASOS data breach?
On October 6, 2026, ASOS confirmed it was investigating a cyber incident after an unauthorized push notification was sent to some customers through third-party platforms ASOS uses to communicate with them. ASOS restricted access to those platforms and reported the incident in a regulatory (RNS) filing the same day.
What personal data was exposed in the ASOS breach?
ASOS and the UK's National Cyber Security Centre (NCSC) say basic personal information, including customer names and contact details, may have been accessed. ASOS does not believe payment card information or account passwords were affected.
Am I affected if I didn't get the ASOS hacked notification?
Yes, you should still assume you're affected. The NCSC's advisory says any ASOS customer should assume they are affected by this incident, even if they personally never received the unauthorized push notification, since notifications only reached some customers and depend on app and device settings.
Is the Xuanye Group's Snowflake claim confirmed?
No. A group calling itself Xuanye Group claimed on its own Telegram channel to have compromised a Snowflake cloud environment tied to ASOS. Neither ASOS nor the NCSC has confirmed this claim, the group's identity, or any specific number of affected customers, so it should be treated as an unverified attacker claim, not a confirmed fact.
What should ASOS customers do right now?
The NCSC recommends assuming you're affected, watching for suspicious messages (which can arrive well after the breach was disclosed), avoiding links in unexpected notifications or emails, reporting any fraud via the UK's Stop! Think Fraud service, and securing your ASOS account with a passkey or a strong, unique password plus two-step verification.
Were ASOS passwords or payment details leaked?
ASOS says it does not believe payment card information or account passwords were affected by this incident, based on its investigation so far. The company has said it will provide updates if that assessment changes.
Sources
- NCSC - Incident affecting ASOS customersncsc.gov.uk
- ASOS plc - Update regarding cyber incident (RNS, 6 Oct 2026)tools.euroland.com
- NCSC - Data breaches: guidance for individuals and familiesncsc.gov.uk
- NCSC - Phishing scams: how to spot and report themncsc.gov.uk
- Stop! Think Fraud - Reporting fraudstopthinkfraud.campaign.gov.uk
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


