Asos Investigates After Thousands Receive 'Asos Hacked' Phone Alert

Thousands of Asos app users received a notification on 6 October 2026 claiming hackers had fully compromised the retailer's data, and Asos is now investigating. The Guardian
The notification was titled "Asos hacked" and held a link to Telegram, a messaging service. Customers shared screenshots as it spread, and the message threatened to leak Asos's information. The Mirror
The customer alert contained a note addressed to staff: "Dear Asos DPO [data protection officer] and IT, we have fully compromised the Snowflake instance." That claim is unverified.
Snowflake is a cloud platform for storing, processing and analysing data, including transactions and details such as clothing sizes and body measurements. Think of it as the stockroom behind the online shop. The claim pointed to that data system, not the storefront itself.
On Tuesday morning, 6 October 2026, the Asos website and app appeared to keep operating. As of that date, Asos was still investigating whether any hack had taken place. Asos shares on the London Stock Exchange fell almost 12% after the notifications were sent.
The broader context here is uncertainty, not confirmation. A push-notification system that reaches thousands of customers is a sensitive control point in itself. Whether the Snowflake claim proves accurate or not, putting a message for security staff into a customer alert suggests an attempt to create visibility and pressure outside normal channels. The Telegram link fits that logic, giving an off-platform place for further claims or supposed samples while checks continue.
Looking at what this means for Asos and its customers, investigators will need to establish whether the Snowflake instance was accessed, whether any transaction or size data left it, and how the push system was used. For customers, the risk divides in two. If data was taken, those transaction and measurement categories are directly relevant. If not, the method still matters, because trust in app alerts affects phishing exposure and response to real security advice. In my view, the market move reflects that double exposure. Investors priced the claim before it could be verified.


