October 6, 2026, 1:42 pm | Read time: 3 minutes
Unknown individuals have apparently taken control of a system belonging to the online fashion retailer Asos and spread a threat via the official app. The senders claim to have fully compromised a central data environment. Whether customer information was copied has not yet been confirmed. Users should refrain from opening the link contained in the push notification for now.
Hackers Use Push Notification for Threat
Asos typically informs its customers via push notifications about orders, offers, and other news. However, a message from alleged hackers with the headline “Asos hacked” appeared in the app, directed at the IT department and the data protection officer.
The senders claimed to have taken over a critical data system of the British company. They urged Asos to contact them via a specified Telegram channel. Otherwise, they threatened to release the allegedly obtained data.
Specifically, the fashion retailer’s Snowflake instance is said to have been fully compromised. Snowflake is a cloud-based environment that companies use to store, process, and analyze information. There is currently no evidence of a successful data theft.
It is also unknown who is behind the threat and why Asos was targeted. The fact that the message could be spread via the official app suggests unauthorized access to the push notification system. However, the exact access route remains unclear.
Nintendo Hacked! Here’s What Happened
Hackers Claim Responsibility for FBI Attack
Order and Body Measurement Data Could Be Affected
Asos is also said to use Simon AI via Snowflake. The system compiles information about individual customers’ behavior and purchases into profiles. These datasets can be supplemented with demographic information.
The stored information could include order data as well as clothing sizes and body measurements. So far, there is no evidence that the senders were able to access this information or that they copied any data. There are also no indications of other compromised systems.
Asos primarily sells clothing, shoes, accessories, and cosmetics through its website and app. At the time of the reports, the company had not publicly confirmed the alleged attack. Details about the type and extent of potentially stolen data were also not available.
Also of interest: Record Returns 2026! Why Online Shopping Could Become More Expensive Now
Website and App Remain Accessible
Despite the suspicious push notification, the website and the Asos app are currently still accessible. Apart from the message, there were no visible signs of an attack. The website also appeared outwardly unaltered.
On Downdetector, nearly 500 reports of potential issues with the Asos website appeared shortly before 10 a.m. Whether technical disruptions were present or customers were merely reporting due to the push notification remains unclear.
The reports of the potential attack also affected the company’s stock price. The Asos stock temporarily lost 11 percent. Before the incident became known, its value had increased by more than 70 percent since the beginning of the year.