Published: 06 October 2026. The English Chronicle Desk. The English Chronicle Online.
Online fashion retailer Asos has launched an investigation after thousands of customers received a disturbing mobile notification claiming that hackers had gained full access to the company’s data. The unexpected alert, which appeared directly on users’ phones, triggered immediate concern among shoppers and sent the company’s shares sharply lower as questions grew over whether a significant cyberattack had taken place.
The notification was titled “Asos hacked” and contained a link directing recipients towards the Telegram messaging service. The message appeared to address Asos’s data protection and information technology teams, claiming that attackers had “fully compromised” a Snowflake instance connected to the retailer.
The wording of the notification raised concerns because Snowflake is a major cloud-based data platform used by businesses to store, process and analyse large quantities of information. Such systems can contain commercially sensitive material as well as customer-related data. The appearance of a message apparently linked to the company’s mobile infrastructure also raised the possibility that attackers may have gained access beyond a conventional database.
However, there was no immediate confirmation that Asos’s customer database had actually been stolen or that the company’s wider systems had been compromised. The retailer’s website and mobile application continued to operate on Tuesday morning, while investigations were under way to determine whether the notification represented a genuine breach, an attempted extortion campaign, or another form of malicious activity.
The incident nevertheless had an immediate impact on financial markets. Asos shares fell by almost 12% on the London Stock Exchange after customers began reporting the alarming notification. The sharp decline reflected investor concerns about the possible financial, legal and reputational consequences of a major data breach at a large online retailer.
For customers, the most immediate concern is whether personal information could have been exposed. Modern online retailers hold considerable amounts of data about their users, ranging from contact and delivery information to transaction records and account details. Depending on the systems involved, databases can also contain information used to personalise products and services.
The reported reference to Snowflake has therefore attracted particular attention from cybersecurity specialists. The cloud platform is designed to allow organisations to store and analyse data at scale and is used across numerous industries. A compromise involving such an environment could potentially have serious consequences if attackers were able to access sensitive records.
Cybersecurity experts have also highlighted another worrying feature of the incident: the hackers’ apparent ability to reach consumers directly through the retailer’s notification system.
Rather than simply sending a ransom message to the company, the attackers appear to have used a channel capable of reaching customers’ mobile devices. Security specialists described this as an aggressive form of public extortion, because it places pressure on a company by making the alleged breach visible to its customers.
The approach could also create a second layer of risk. Even if the original incident turns out to be limited, the publicity surrounding it could provide an opportunity for unrelated criminals to impersonate Asos and target worried customers.
Shoppers may receive fraudulent emails, text messages or other communications claiming to provide information about the alleged breach. Criminals could use the situation to encourage people to reset passwords, verify payment information, review recent purchases or request refunds through fake websites.
Cybersecurity professionals have consequently urged customers to be particularly cautious about unexpected messages appearing to come from Asos. People should avoid clicking unfamiliar links in emails or text messages and should instead access their accounts through the company’s established website or application.
Customers should also be wary of messages creating a sense of urgency. Cybercriminals frequently exploit fear during major security incidents by claiming that an account is at immediate risk or that action must be taken to prevent financial loss. Such messages can be convincing precisely because users already know that a genuine security incident may have occurred.
The Asos situation comes against a wider backdrop of increasing cyber threats facing major British retailers. Several prominent companies have experienced serious cyber incidents in recent years, demonstrating how attacks against retail organisations can extend beyond stolen information and disrupt everyday commercial operations.
Marks & Spencer and the Co-op were among the retailers affected by cyber incidents during the previous year. Their experiences demonstrated the potential operational consequences of attacks on large businesses. Disruption to information technology systems can affect websites, supply chains, stock management and payments, leaving customers facing shortages or delays.
For Asos, whose business depends heavily on digital systems, any prolonged technology disruption could be particularly damaging. Unlike a retailer with a large network of physical stores, an online fashion company relies extensively on its digital infrastructure to display products, process orders, communicate with shoppers and manage customer accounts.
That makes the reported notification especially significant. If the claims ultimately prove to be genuine, Asos could face not only the technical challenge of securing its systems but also questions about how attackers gained access and what information may have been exposed.
The company could also face regulatory scrutiny if customer data were found to have been compromised. Data protection rules require businesses to take appropriate steps to safeguard personal information and to respond properly when serious breaches occur. The scale and nature of any potential regulatory response would depend on what investigators establish about the incident.
At the same time, caution is necessary because the notification itself does not establish the full extent of any cyberattack. A message claiming that systems have been compromised can be part of a genuine extortion attempt, but such claims can also be exaggerated or misleading. Until Asos completes its investigation, customers and investors may have to wait for a clearer picture.
The unusual method used to distribute the warning has nevertheless heightened concern. Receiving a cyberattack message through an official-looking mobile notification can make an alleged breach feel considerably more immediate to consumers than a conventional report appearing in the media.
For thousands of Asos customers, the episode therefore represents more than a temporary disruption. It is a reminder of how closely modern shopping is connected to digital infrastructure and how quickly a suspected cyber incident can move from a company’s internal systems into the public domain.
The retailer now faces the difficult task of establishing what happened while maintaining confidence among customers and investors. If no significant breach occurred, Asos will need to explain how such a message reached customers and whether its notification infrastructure was misused. If a breach is confirmed, the company will face the considerably larger challenge of determining what data was accessed, containing the intrusion and communicating transparently with those affected.
Until more information becomes available, customers are being encouraged to remain alert rather than panic. They should monitor their accounts for unusual activity, treat unexpected requests for personal or payment information with suspicion and avoid links contained in unsolicited messages.
The incident also highlights the broader challenge facing retailers as they become increasingly dependent on cloud platforms and interconnected digital services. The same technologies that allow companies to process vast amounts of information efficiently can become attractive targets for criminals seeking valuable data or leverage over major businesses.
Asos’s investigation will ultimately determine whether Tuesday’s alarming notification was evidence of a serious compromise or an attempted cyber-extortion campaign that overstated the attackers’ access. For now, the continuing operation of the company’s website and app offers some reassurance, but the sharp market reaction and direct warning received by customers show why the claims are being treated seriously.
The coming days are likely to be closely watched by customers, investors and cybersecurity professionals as Asos works to establish the facts and determine whether any personal or commercial information was exposed.




























































































