ASOS has confirmed it is investigating unauthorised activity after hackers used its customer communications infrastructure to send a notification to shoppers on Tuesday, with the retailer saying some basic personal information may have been accessed.
ASOS said the unauthorised notification was sent at around 10am on 6 October through third-party platforms it uses to communicate with customers. The message, headed "ASOS HACKED", claimed attackers had fully compromised a Snowflake instance and threatened to leak data unless the retailer engaged with them.
The company said it had taken immediate action to restrict access to the notification platforms and was working with internal and external specialist advisers and relevant authorities. ASOS said its website and app were operating normally, with no current disruption to its operations.
ASOS said the information potentially accessed included "basic personal information including name and contact details". The retailer said it did not believe payment-card information or account passwords had been impacted.
The notification directed customers towards a Telegram channel linked to a group calling itself the Xuanye Group. The group claimed it had compromised ASOS's Snowflake environment and subsequently said payment information had not been affected, although those claims have not been independently verified.
Snowflake said it began investigating after becoming aware of the notification and had found no evidence that its platform had been compromised. Katherine James, director of Snowflake's Europe, Middle East and Africa communications team, told the BBC: "At this time, we can report that we have found no compromise of the Snowflake platform."
The finding conflicts with the attackers' claim that they had "fully compromised the Snowflake instance", leaving questions over how the unauthorised notification was sent and which systems may have been accessed. ASOS has not said how the attackers gained access to its customer communications platforms.
The National Cyber Security Centre has offered assistance to ASOS, according to the BBC, while the Metropolitan Police is aware of reports concerning an alleged cyber incident involving a company in Camden. The number of customers who received the notification and the full extent of any data access remain unclear.
ASOS said it was too early to quantify any potential impact from the incident and confirmed it had cyber-security insurance, including business continuity cover. It said the investigation was continuing and that further information would be provided if the situation changed.
"Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate," ASOS said.










Recent Stories