Drooid Logo
Back to story perspectives

Full Breakdown

ASOS Data Breach Exposes Customer Profiles and Triggers Market Reaction

By Drooid · · How we work

Unauthorized Notification and Data Exposure

On October 6, 2026, ASOS customers received a pop-up titled “ASOS HACKED.” The message, addressed to the retailer’s data-protection officer and IT team, claimed the hackers had “fully compromised the Snowflake instance” and linked to a Telegram channel. The exposed data includes names, addresses, phone numbers, email addresses, account numbers and recent search terms such as “reclaimed vintage” and “glamorous wide fit.” The company said no payment-card details or passwords were believed to be compromised.

How the Attack Was Executed

ASOS said the breach began when an unauthorised party gained access to an employee account by impersonating a trusted contact to obtain login credentials. Those credentials were then used to reach third-party platforms that support ASOS’s services. Snowflake’s investigation found no evidence of a breach of its platform.

Timeline of Key Events

  • October 6, 2026 – Unauthorized push notification appears on customers’ phones.
  • Later on October 6 – ASOS restricts access to the notification platform and launches an investigation with internal and external specialists and authorities.
  • Following days – Market reaction and public advisories are issued.

Data and Statistics

Outlets describe the breach as affecting “potentially millions” of users, though the exact number has not been disclosed. In addition to contact details, the stolen dataset contains search-history terms that reveal individual shopping preferences.

Official Statements & Responses

ASOS emailed customers urging caution against unexpected messages or calls claiming to be from the retailer and emphasized that it will never request passwords, security codes or payment details via unsolicited contact. The company affirmed that its website and app continue to function normally and that it is cooperating with law-enforcement and regulators. The UK National Cyber Security Centre offered assistance, and Snowflake confirmed its platform shows no sign of compromise.

Market Impact and Analyst View

The breach coincided with a sharp decline in ASOS’s share price, which later recovered partially. Bloomberg Intelligence analyst Charles Allen warned that the loss of customer trust could temporarily curb ASOS’s efforts to revive sales and profits.

Criticism & Opposition

Charlotte Wilson, head of enterprise for the UK & Ireland at Check Point, highlighted the risk inherent in app-based notifications, noting that “millions of people trust notifications from apps on their phones because they are supposed to come directly from the company.” Consumer-rights spokesperson Kat Cereda advised customers to be “extremely suspicious” of unsolicited communications claiming to be from ASOS and to verify any contact through independent channels.

Conflicting Reports & Gaps

  • Extent of data accessed – ASOS describes the breach as involving “basic personal information,” while the hackers claim full compromise of the Snowflake instance. Snowflake’s statement contradicts the latter claim.
  • Share-price movement – Some reports describe a decline of more than 10 % in ASOS’s share price, whereas Reuters later noted a modest rebound of about 3 % after the initial drop.
  • Number of affected customers – No source provides a definitive count; estimates remain vague.

Verbatim Quotes

  • “We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials,” — ASOS
  • “In a statement, the company said: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers.” — ASOS
  • “We do not believe that payment-card information or account passwords, were impacted,” — ASOS