ASOS cyber attack: Australian and UK customers sent threatening message as retailer investigates data breach

Hackers have sent a chilling message directly to ASOS customers, sparking fears over what information may have been compromised.

Headshot of Madeline Cove
Madeline Cove
The Nightly
ASOS shoppers received alarming notifications claiming hackers have fully compromised the retailer's Snowflake data platform, demanding engagement or threatening to leak customer information.

Australian ASOS customers have received a chilling message apparently sent by hackers threatening to leak information after claiming they had “fully compromised” part of the fashion giant’s systems.

The alarming notification landed on customers’ phones on Tuesday evening and appeared to directly address ASOS’s data protection and IT teams.

“Dear ASOS DPO and IT, we have fully compromised the Snowflake instance,” the message reads.

Sign up to The Nightly's newsletters.

Get the first look at the digital newspaper, curated daily stories and breaking headlines delivered to your inbox.

Email Us
By continuing you agree to our Terms and Privacy Policy.

“Engage with us, or we will leak it,” it continues, before directing recipients to a Telegram chat.

Customers in both Australia and the UK received the message, sparking immediate fears that the online fashion retailer had suffered a major cyber attack.

ASOS has since confirmed it is investigating “unauthorised activity” and warned some customer information may have been accessed.

In a statement released in the early hours of Wednesday morning, the retailer said “basic personal information including name and contact details may have been accessed.”

However, ASOS said it did not believe customers’ payment information or account passwords had been compromised.

The company has an estimated 17 million customers across 150 countries, although it remains unclear how many accounts may have been affected or how many Australian shoppers are potentially caught up in the incident.

The message appeared to be directed at ASOS’s data protection officer, referred to as its DPO, and IT team.

Snowflake, meanwhile, is a cloud-based data platform used by companies to store and manage information.

The extraordinary notification quickly sent customers scrambling for answers, with hundreds taking to social media to question whether their information was safe.

“Has ASOS been hacked..this push notification is crazy,” one customer said.

Another revealed they had immediately removed their stored payment information.

“ASOS hacked, never deleted my payment details so quick.”

Others found humour in the bizarre incident.

“ASOS wouldn’t give me a refund last week now look. Getting what they deserve,” another customer wrote.

The apparent cyber incident also coincided with a sharp fall in ASOS shares.

The retailer’s shares plunged 12.5 per cent following the threatening message at about 8pm on Tuesday, wiping an estimated $133 million from its value.

The incident comes as the British online fashion retailer battles broader financial pressures.

ASOS previously reported revenues of about $4.75 billion in 2025, down from approximately $5.51 billion the previous year.

Attention will now turn to the scale of the apparent breach and exactly what information may have been accessed.

ASOS has not yet revealed how many customers were potentially affected, including the number of Australian accounts caught up in the incident.

The company’s investigation into the unauthorised activity is continuing.

Comments

Latest Edition

Defence Horizon magazine cover image.

Latest Edition

Edition Edition 7 October 20267 October 2026

WA’s defence boom: what it means for you