‘Hacked’ Alert Appears in ASOS App: What Has Been Confirmed and What Remains Unknown

ASOS users’ mobile phones displayed a push notification reading “ASOS HACKED” on the morning of October 6.

The notification claimed that the company’s data platform had been completely compromised and threatened to leak information if its demands were not met.

However, the notification alone does not confirm that customer information was leaked or establish the actual scope of the alleged breach.

3-line summary
1. An alert claiming a hack was sent through the ASOS app
2. The alert contained a leak threat and a Telegram link
3. Whether personal information was leaked has not been confirmed

Warning Appearing on App Users’ Screens on October 6

According to reports by STV News and the London Evening Standard, a push notification was sent to many ASOS mobile app users on the morning of Tuesday, October 6. Along with the words “ASOS HACKED,” the notification contained a message apparently addressed to ASOS’s data protection officer (DPO) and information technology department.

The message’s author claimed to have “completely compromised the Snowflake instance.” It then threatened to leak information unless the company made contact and included a link to a Telegram chat. Snowflake was described as an online data platform used by companies to store, analyze, and share large volumes of data.

ASOS had not confirmed whether the notification came from an actual attacker or whether the alleged breach was genuine. At the time of reporting, ASOS had reportedly not immediately responded to requests for comment and had not issued separate guidance concerning the notification or a possible cyberattack.

Website and App Continued to Work, but Share Price Fell

Even after the notification was sent, the ASOS website and app appeared to be operating as usual. The London Evening Standard reported that, as of 10:30 a.m., more than 400 reports had been submitted to Downdetector, which tracks reports of website and app outages. This was a figure for reports concerning service-access problems, not evidence that data had been leaked.

According to The Independent and the London Evening Standard, ASOS shares fell by about 12.5% after the notification was sent. The Independent reported that the company’s value had fallen by about £70 million, based on the decline after 10 a.m. Although the market reaction was significant, share-price movements do not establish that a breach occurred or confirm the scale of any damage.

ASOS was reported to have more than 150 million customers annually across more than 1,700만 countries (1700만, or approximately 17 million). Until the company provides an explanation, the notification’s reach and the scale of its actual impact also remain unknown.

Users Should Avoid Opening the Telegram Link

Cybersecurity expert Junaid Ali advised The Independent’s readers not to click the Telegram link in the notification. Regardless of whether the hacking claim is genuine, external links in threatening alerts can lead to further fraud or attempted account takeovers.

He said users should use long, unique passwords for each account and enable two-factor authentication where possible. In this case especially, changing passwords or deleting payment methods should not be understood as measures based on an assumption that an actual leak occurred. The fact currently confirmed is that a push notification claiming a hack was sent; whether customers’ personal information was actually stolen has not been confirmed.

References

Tags #ASOS #ASOSHacking #HackingAlert #PushNotification #Cyberattack #DataLeak #PrivacyProtection #Snowflake #Snowflake #TelegramLink #AccountSecurity #TwoFactorAuthentication