ASOS warns customers after unauthorised app notification
Source announcement date: 6 October 2026.
Event date: Notification sent at around 10am on 6 October; initial intrusion date undisclosed.
ASOS customers are being warned about an unauthorised notification sent through the retailer’s app on 6 October. The company said the message went out at around 10am and that it was investigating unauthorised activity involving third-party platforms used to communicate with customers.
ASOS said basic personal information, including names and contact details, may have been accessed. It did not believe payment-card information or account passwords had been affected. Its website and app were operating normally when the statement was issued. The company restricted access to the notification platforms and involved specialist advisers and relevant authorities.
The important distinction is between what ASOS has confirmed and what the attackers alleged. The notification claimed its Snowflake data environment had been compromised. That claim was not confirmed in the company statement, and the number of affected customers was not disclosed. The public information does not explain how the attackers initially obtained access.
A message arriving through a familiar app can feel trustworthy. This incident shows why the delivery channel alone cannot guarantee that a notification is genuine. If contact details were accessed, they could potentially help criminals make follow-up scam messages more convincing; that is a possible risk, not confirmation that such scams have occurred.
ASOS’s in-app warning tells customers to disregard the unauthorised alert and avoid its external link. Open the app or website directly for updates. Be cautious about messages asking for payment, passwords or urgent account verification, and independently check unexpected requests before responding.








Comments