ASOS data breach: what happened, and what it means for a small business
Short answer: the ASOS data breach started with a push notification ASOS didn’t send. At around 10am on Tuesday 6 October 2026, ASOS app users got a message from attackers, and ASOS says it’s investigating unauthorised activity on the third-party platforms it uses to message customers. Names and contact details may have been accessed, but ASOS doesn’t believe card details or passwords were. Small businesses aren’t ASOS, but most of them message their customers through other companies’ tools too. Here’s what’s known about the ASOS hack, what isn’t, and what it means for a firm of five or fifty people.
Not sure who could message your customers as you? Ring 0151 452 3060 and a person picks up, or start with the Free Cyber Health Check: six questions and a written fix list.
What happened in the ASOS data breach
At around 10am on 6 October, customers using the ASOS app got a notification headed “ASOS HACKED”, according to BleepingComputer and Bloomberg. It was addressed to ASOS’s data protection officer and IT team rather than to customers: “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.” It linked to a Telegram channel.
Shortly after 3pm, ASOS confirmed it in a statement to the London Stock Exchange. In its words, it’s “investigating unauthorised activity involving third-party platforms that we use to communicate with customers”. It “took immediate action to restrict access to the notification platforms”. And “basic personal information including name and contact details may have been accessed”. It doesn’t believe payment-card information or account passwords were affected, and its website and app kept working normally.
The National Cyber Security Centre published an alert for ASOS customers the same day. Its advice is worth repeating. Be wary of messages after a breach, and don’t click links in notifications, emails or texts you weren’t expecting. Use strong, unique passwords or passkeys, turn on two-step verification, and keep an eye on your accounts. It also said customers who didn’t get the notification should assume they may be affected.

The ASOS hack: what’s known, and what isn’t
- Confirmed by ASOS: the notification was unauthorised, it went out through third-party customer-communication platforms, and names and contact details may have been accessed.
- Not believed affected, per ASOS: card details and passwords.
- Claimed by the attackers, not verified: a group calling itself “Xuanye” says it holds ASOS customer data and has set a deadline. Bloomberg reported that it gave no evidence and couldn’t verify the claim.
- Denied: Snowflake, the cloud data platform named in the message, told Bloomberg it “found no compromise of its platform”.
- Not known: how the attackers got in, which platform it was, and how many customers are affected. Anyone telling you otherwise is guessing.
The share price fell as much as 15% during the day, according to Bloomberg. In its statement, ASOS noted it has cyber insurance, including business continuity cover.

Lesson 1: the ASOS cyber attack didn’t need the website
The detail that matters most for a small business is the route. Nobody had to break into the ASOS checkout. The message came through a tool ASOS uses to talk to its customers, so it arrived with ASOS’s name on it, on customers’ own phones.
Small businesses work exactly the same way, just on a smaller scale. Think about every service that can send a message to your customers in your name. Your email marketing tool. The system that sends invoices and reminders. Your booking or appointment software, the text service, and your Microsoft 365 mailbox itself. Each one has a login. If somebody else has that login, they can message your customers as you, and your customers have every reason to believe it.
So the first job is a list. Write down every tool that can contact your customers, who has an account on it, and whether that account uses two-step sign-in. For most small firms that’s five or six tools and a ten-minute job. It’s the same discipline as checking your suppliers, applied to the tools you log into every day.
Lesson 2: the phishing wave that follows is the bigger risk
For most businesses, the risk this week isn’t ASOS’s data. It’s the emails that will now land in your team’s inboxes pretending to be ASOS: refund offers, “verify your account” messages, compensation vouchers. Plenty of your staff are ASOS customers, and a convincing breach email opened on a work laptop is a work problem.
That’s how most attacks start. The government’s Cyber Security Breaches Survey 2025 found 85% of UK businesses that identified an attack said phishing was involved. A headline breach just gives the criminals a ready-made, believable story. A two-minute word at Monday’s meeting helps: if an email about the ASOS data breach asks you to click, sign in or confirm anything, go to the app or website yourself instead.
This is what our IT support already covers
Email filtering that catches lookalike and impersonation emails before anyone reads them. Short phishing practice for your team. Multi-factor sign-in on every Microsoft 365 account, and automatic lock-out when an account is used from somewhere it shouldn’t be. It’s all in our managed IT support at £55 a person a month, and moving to us takes a week with nothing for your team to prepare.
Lesson 3: know what you’d tell your customers
ASOS had a statement out within about five hours. Most small businesses have never thought about what they’d say, or who’d say it, if their customers got a message they didn’t send. A one-page plan answers four questions in advance. Who decides what happens? Who tells customers, and how? Who tells the ICO if personal data’s involved? (Under UK GDPR that’s within 72 hours of finding a reportable breach.) And who rings the insurer?
On insurance, ASOS mentioned its cover in its very first statement. If you have a cyber policy, the insurer will have asked about two-step sign-in, backups and staff training on the proposal form. Our guide to cyber insurance requirements explains what they ask and what evidence answers it.
ASOS isn’t the first big name this has happened to. For how the ASOS cyber attack compares with M&S, the Co-op and Jaguar Land Rover, and the patterns all four share, see what the UK’s biggest cyber attacks teach a small business. And for three earlier cases where the way in was a supplier, see supply chain attacks: three real cases.
A five-point check for this week
- List every tool that can message your customers, and who can log in to each.
- Turn on two-step sign-in on all of them, starting with the admin accounts.
- Remove anyone who’s left, and any shared logins nobody owns.
- Warn your team about ASOS-themed emails, and tell them who to ask if something looks off.
- Write the one-page plan: who decides, who tells customers, who rings the ICO and the insurer.
None of that needs new software. It’s the same short list of basics in our cyber security guide for small businesses, and it’s what stops most attacks on a firm your size. DSIT found 43% of UK businesses reported a breach or attack in the last year, so the odds aren’t small.
ASOS data breach: questions people are asking
What happened in the ASOS data breach?
On 6 October 2026, an unauthorised push notification was sent to ASOS app users. ASOS said it was investigating unauthorised activity on third-party platforms it uses to communicate with customers, and that names and contact details may have been accessed.
Were ASOS passwords or card details stolen?
ASOS says it doesn’t believe payment-card information or account passwords were affected. It says names and contact details may have been accessed.
How did the ASOS hackers get in?
That hasn’t been disclosed. ASOS has only said the activity involved third-party platforms it uses to message customers. Snowflake, named in the attackers’ message, says it found no compromise of its platform.
What should ASOS customers do?
The NCSC advises treating unexpected messages with suspicion, not clicking links in notifications, emails or texts you weren’t expecting, using strong unique passwords or passkeys, turning on two-step verification and checking your accounts. It says customers who didn’t get the notification should assume they may be affected.
What does the ASOS cyber attack mean for a small business?
Two things. Any tool that can message your customers can be used against you if someone gets the login, so protect those logins with two-step sign-in. And expect ASOS-themed phishing emails to reach your staff over the coming weeks.
Written by Eric Lonsdale
I’ve spent twenty years securing systems for hospitals, government and national infrastructure, and now I look after small offices across Liverpool, the Wirral and Cheshire. We work to the NCSC’s frameworks and run to Cyber Essentials standards, and new clients are Secured in 7 Days, or that month is on us.
Want a second pair of eyes on it? Ring Eric this week on 0151 452 3060 and we’ll go through your customer-facing tools and the five points above together. Or start with the Free Cyber Health Check: six questions, a written fix list.
Sources
- ASOS plc, “Update regarding cyber incident”, London Stock Exchange announcement, 6 October 2026.
- National Cyber Security Centre, “Incident affecting ASOS customers”, 6 October 2026.
- Bloomberg, “ASOS says cyberattack may have compromised customer data”, via Insurance Journal, 6 October 2026.
- BleepingComputer, “ASOS confirms data breach after ‘HACKED’ in-app notifications”, 6 October 2026.
- Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025.
Facts as at 7 October 2026. We’ll update this page if ASOS publishes more.
