On Tuesday morning, millions of ASOS customers received a push alert within the shopping app warning of a potential hack. The alert, mistakenly sent to users but targeted at ASOS’s internal data protection and IT teams, has raised alarms about the company’s data security and the possible exposure of customer information.

  • Push alert wrongly sent to ASOS customers suggesting a hack
  • Security experts flag potential data exposure via SaaS platform Snowflake
  • Customers advised against clicking links or responding to suspicious messages

What happened

On the morning of October 6, ASOS customers globally received a push notification through the app bearing the alarming headline “ASOS HACKED.” The message appeared to be intended for the company’s internal data protection officer and IT team but was erroneously broadcast to users instead. This incident coincided with a surge in reports of app issues on outage monitoring sites.

The notification referenced 'Snowflake,' the cloud-hosted data warehousing service that ASOS uses via its marketing AI platform Simon. This unintentional disclosure has caused concern that customer data — including purchasing behaviors, locations, and loyalty details — could be compromised, though the exact impact remains unclear at this time.

Why it matters

ASOS serves approximately 17 million customers worldwide, making the security and privacy of its data a critical matter. The potential unauthorized access to detailed customer profiles could facilitate identity theft, targeted scams, or other malicious activity. Cybersecurity researchers emphasize that the indirect connection through a SaaS data warehouse complicates immediate understanding of the breach’s breadth.

Amid ongoing digital threats, such exposure risks undermine consumer trust and raise questions about safeguarding sensitive data in complex cloud environments. The incident also underscores the dangers of notification system errors that can amplify fear and confusion without clear official communication.

What to watch next

ASOS has yet to issue a public statement clarifying the situation or confirming whether a breach occurred. Customers should monitor official channels for updates and remain vigilant against phishing attempts, particularly messages urging password resets or linking to platforms like Telegram, which were referenced in the alert.

Cybersecurity experts recommend temporarily avoiding transactions on the ASOS platform until more details emerge. Observers will be watching for ASOS’s response, potential security improvements, and any regulatory actions that may follow this notable security incident.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings