ASOS 'hacked' live —all the latest as customers receive threatening alert
The online shopping giant ASOS has seemingly been hacked today , with customers receiving a threatening notification from the mobile app.
<![CDATA[ <article> <div class="live-content"><p>The online shopping giant ASOS has <a href="https://www.techradar.com/pro/security/asos-hacked-customers-receive-threatening-notification-from-hackers-heres-what-we-know">seemingly been hacked today</a>, with customers receiving a threatening notification from the mobile app.</p><p>The message (titled "ASOS HACKED") was sent on Tuesday morning via a push alert in the ASOS app and security experts have told us that "the potential scope is significant". We've contacted ASOS, but so far it hasn't publicly commented on the issue.</p><p>You can follow all the latest developments live with us, including the latest advice on what you should do if you're one of the site's 17 million global customers...</p><h2 id="potential-asos-hack-the-latest-news">Potential ASOS hack — the latest news</h2><ul><li><strong>ASOS customers reported receiving a threatening alert on Tuesday morning</strong></li><li><strong>The alert was titled 'ASOS Hacked' and linked out to a Telegram chat</strong></li><li><strong>ASOS hasn't yet officially commented on the security issue</strong></li></ul></div><div class="live-content"><h2 id="what-did-the-alert-say">What did the alert say?</h2><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2107394700613132752"><p lang="en" dir="ltr">Anyone else get the ASOS hacked notification? Any ideas? https://t.co/WZkWta5dek<a href="https://twitter.com/cantworkitout/status/2107394700613132752">October 6, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>ASOS customers first reported receiving the push alert above on Tuesday morning at around 4.55am ET / 9.55am BST.</p><p>This coincided with a spike in reports on <a href="https://downdetector.co.uk/status/asos/" target="_blank">Downdetector</a>. The message is addressed to ASOS' data protection officer (DPO) and IT team, but was sent to customers.</p><p>The 'Snowflake' the message refers to is a Software-as-a-Service (SaaS) that organizations use as a dedicated cloud environment to store, process, and analyze data. This is what has concerned security experts, although it's a little early to say whether customer data has been compromised.</p></div><div class="live-content"><time datetime="2026-10-06T12:25:40+00:00">October 6, 2026 – 8:25 AM</time><h2 id="what-should-you-do">What should you do?</h2><p>Did you get the ASOS 'hacked' notification? If so, there are a few important things that you shouldn't do, including clicking the Telegram link in the message. You should also:</p><ul><li><strong>Avoid clicking links in any suspicious emails</strong></li><li><strong>Do not click links in any suspicious texts or messages</strong></li></ul><p>Other cybercriminals could try to exploit the hysteria caused by the ASOS notification, so you should be particularly wary of emails telling you your account has been compromised, or asking you to reset your password.</p><p>It's also wise to be careful about shopping on ASOS until the company comments publicly on the issue, which hasn't happened yet.</p></div><div class="live-content"><time datetime="2026-10-06T12:40:21+00:00">October 6, 2026 – 8:40 AM</time><p>We've been hearing from cybersecurity experts on the potential implications of the ASOS notification.</p><p>Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes, told TechRadar Pro, "It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect."</p><p>"Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access," Arntz said.</p></div> </article> ]]>
Read the full article on TechRadar
Read Full Article →