UK online retailer ASOS has warned that basic personal details may have been accessed after an unauthorised alert went to customers on 6 October.
The company said that the data involved covers names and contact details.
Discover B2B Marketing That Performs
Combine business intelligence and editorial excellence to reach engaged professionals across 36 leading media platforms.
“We do not believe that payment-card information or account passwords, were impacted,” it added.
A message from the hackers, as reported by multiple media outlets, read: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
ASOS said in its statement: “We are investigating unauthorised activity involving third-party platforms that we use to communicate with customers. We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers, as well as all relevant authorities.”
The retailer added: “Our website and app are operating as normal, with no current disruption to any aspects of our operations. Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate.”
The National Cyber Security Centre (NCSC) advised customers to assume they are affected, whether or not they received the alert.
It urged them to watch for suspicious messages, which may appear some time after an incident, and to avoid clicking dubious links, whether sent by push notification, email or message.
The NCSC also said passkeys, or strong, unique passwords combined with two-step verification, protect accounts even if their data is breached.
ASOS said it holds cyber security insurance with a large global provider, which also includes business continuity cover.
It said it is “too early” to quantify any potential effect on trading.
Last year, several other UK retailers also reported cyber incidents.
Marks and Spencer faced one in April 2025, the same month the Co-op also had customer data breaches.
Harrods alerted some of its e-commerce customers to a data breach in September 2025.
