Tuesday, October 6, 2026
Noti Group
Business

Unauthorized Access Compromises Asos Customer Data

Asos has issued a warning that customer data may have been compromised following unauthorized access to its app systems.

Asos warns customer data may be compromised after ‘unauthorised’ app access
Source: The Guardian Business

Asos, a leading online fashion retailer, has issued a warning that customer data may have been compromised following unauthorized access to its app systems.

The company's shares took a significant hit after thousands of customers received a notification claiming hackers had "fully compromised" the company's data. The value of Asos' shares on the London Stock Exchange plummeted by over 14% before recovering slightly to an 11% decline.

Asos is currently investigating unauthorised access to its app system, which may have exposed basic customer information such as names and contact details. However, the company has stated that it does not believe payment card records or passwords were compromised in the breach.

The unauthorized access was reportedly made through third-party platforms used by Asos to communicate with customers. The company took immediate action to restrict access to these notification platforms and is working closely with internal and external cybersecurity experts, as well as relevant authorities.

Asos' website and app are still operational, with no disruptions reported so far. However, the company has emphasized that customer trust is of utmost importance, and it will provide updates if the situation changes.

Asos has informed its customers that their data may have been compromised after an unauthorized party accessed a cloud platform used by the company.

The affected platform is called Snowflake, which stores and processes sensitive information such as transactions, demographic details, and even body measurements for clothing sizes. This platform also enables push notifications to be sent directly to customers' phones. The hack has raised concerns about potential data breaches and unauthorized access.

Despite the breach, the hackers claim that payment information remains safe, and they have assured Asos customers that their app is secure to use. However, experts are warning against taking this at face value, as the hackers may be trying to manipulate public perception while negotiations with Asos unfold.

In a statement, the National Cyber Security Centre has offered its assistance to Asos in investigating the breach and mitigating any potential damage. This support comes from within the government's GCHQ intelligence agency, highlighting the seriousness of the situation.

Meanwhile, online security experts are warning customers to be vigilant against targeted phishing attempts, which may arise as a result of the hack. Dray Agha, senior manager of security operations at Huntress, has cautioned that the hackers' tactics are aggressive and designed to force Asos into a quick negotiation.

Asos has warned its customers that their data may be at risk following an unauthorized access to the company's app, which has been linked to a group of hackers known as Xuanye.

Sophos' principal threat researcher Aiden Sinnott observed that new hacking groups often wait until they have identified a significant opportunity before announcing themselves in order to gain credibility within the cybercrime ecosystem. This suggests that Xuanye may be a relatively unknown entity prior to this incident, with no previous mentions on hacker forums or Telegram channels.

The potential data breach has created an ideal environment for phishing attacks, according to Marijus Briedis, chief technology officer at NordVPN. Hackers are likely to exploit the publicity surrounding Asos' cyber incident by sending fake emails and texts claiming to be from the company, asking customers to reset passwords or confirm payment details.

The Asos breach is not an isolated incident, as several British retailers including Marks & Spencer, the Co-op, and Harrods experienced cyber incidents last year, leading to stock shortages and website closures.

Facts based on reporting originally published by The Guardian Business.

You may republish this story, in full or in part, if you credit Noti Group and link to it (licence CC BY 4.0). Photos are not included.