Field Notes / Breach Analysis
The ASOS Hack Arrived on Customers’ Lock Screens. Sent From ASOS’s Own App.
On 6 October 2026 ASOS app users woke to an extortion message under the ASOS name. ASOS says an attacker got into an employee’s account by impersonating a trusted contact, then used the company’s own customer-messaging tools to send it. The Snowflake claim is unproven. The lesson is already clear: the system that can message every customer you have is a privileged system, and almost nobody tests it like one.
01 What ASOS has confirmed, day by day
The public record is still thin, and some of what circulated in the first hours came from the attackers. Here is what each party has actually said.
| Date | Who | What they said |
|---|---|---|
| Tue 6 Oct | The attackers | A push notification to app users, signed “Xuanye Group”, addressed to ASOS’s data protection officer and IT staff. It claimed full compromise of a Snowflake instance and demanded negotiation BleepingComputer . |
| Tue 6 Oct | NCSC | “If you are an ASOS customer, you should assume you are affected by this incident”, even without the notification NCSC . |
| Tue 6 Oct, evening | ASOS | An apology email to customers Out-Law . |
| Thu 8 Oct | ASOS | Employee account accessed by impersonating a trusted contact. Names, contact details and some non-personal account data accessed. No cards, no passwords The Record . |
| Thu 8 Oct | Snowflake | Denies any compromise of its platform The Record . |
| Thu 8 Oct | The market | Shares down more than 9.5% from their pre-alert value, after falling over 10% The Record . |
Two numbers are missing. ASOS has not said how many of its 16.5 million customers are affected Out-Law , and it has not said whether data was copied out. Under Article 33 of the UK GDPR a controller reports a notifiable personal data breach to the ICO within 72 hours of becoming aware of it UK GDPR Art. 33 . The ICO has not commented publicly, so we cannot tell you whether that report has been made.
03 The way in was a conversation
“Impersonating a trusted contact” tells you the attacker did not need a software flaw. Someone convinced an ASOS employee that they were a person the employee already worked with, and the employee handed over access. ASOS has not said who was impersonated or over which channel. In our own social engineering work the pretext that lands most often is the same few people: a colleague, an IT helpdesk agent or a supplier contact who seems to need something urgently.
MFA helps less than people hope against this. A one-time code can be read out over the phone. A push approval can be tapped because the caller said it was coming. Phishing-resistant methods such as passkeys and hardware keys hold up better, because the employee has nothing to read out or approve for a stranger. They only protect the systems that actually enforce them, and SaaS tools bought by a single department often sit outside the company’s single sign-on altogether.
Pinsent Masons’ Laura Gillespie called the incident “at a very early stage of investigation” Out-Law . Fair. You do not need the final report to test whether the same conversation would work on your own staff.
04 Five checks for your own messaging stack
- List every tool that can send to customers. Push, SMS, email marketing, in-app messaging, CRM journeys, and the agency accounts attached to them. Marketing will know about tools security has never heard of.
- Put them behind single sign-on with phishing-resistant MFA. Where a tool cannot do that, record who owns the exception and when it gets reviewed.
- Separate writing from sending. A message to the whole audience should need a second person to approve it. Most platforms support this, and few companies switch it on.
- Find the API keys. Search repositories, CI variables and shared drives for send-capable keys. Rotate any you find, and scope new ones to the smallest audience that works.
- Test the trusted-contact call. A social engineering exercise against the people who administer these tools tells you whether your helpdesk and marketing team would hand access to a convincing stranger. That has to be in the scope explicitly, because no scanner will tell you.
ASOS will publish more as the investigation runs, and some of this may change. The question for your own business will stay the same. If an attacker got hold of the one account that can reach every customer’s phone, would anyone on your team know before your customers did?
References
Sources
- NCSC. Incident affecting ASOS customers. 6 October 2026. ncsc.gov.uk
- The Record. ASOS says hackers tricked employee to gain access, send push notification. 8 October 2026. therecord.media
- BleepingComputer. ASOS confirms data breach after hacked in-app notifications. October 2026. bleepingcomputer.com
- Pinsent Masons, Out-Law. ASOS cyber attack leaves UK businesses and customers reeling. 7 October 2026, updated 8 October. pinsentmasons.com
- UK GDPR, Article 33: Notification of a personal data breach to the supervisory authority. legislation.gov.uk