
ASOS Hacked Message: What Customers Should Do to Protect Themselves
ASOS Customers Receive Hacked Message
The alarming notification appeared on Tuesday, October 6, and claimed that hackers had compromised an ASOS “Snowflake instance”. The message threatened to leak information unless the company engaged with the attackers.
ASOS has confirmed that an unauthorised notification was sent to some customers and said it is investigating activity involving third-party platforms used to communicate with shoppers.
The company said basic personal information, including customer names and contact details, may have been accessed. However, ASOS said it does not currently believe payment-card information or account passwords were affected.
Do Not Click the Link
The first and most important step for anyone who received the message is simple: do not click the link included in it.
ASOS has specifically told customers to disregard the unauthorised notification and avoid engaging with the external link.
The message reportedly directed users towards a Telegram channel. Cybersecurity experts have warned that links connected to a cyberattack can expose users to further scams, phishing attempts or malicious websites.
Customers should also avoid contacting the people behind the message.
Instead, any information about the incident should be obtained directly from ASOS’s official website or customer service channels.
Should You Change Your ASOS Password?
ASOS currently says customers do not need to change their passwords because the company does not believe account passwords were affected.
However, customers who use the same password on ASOS and other websites should consider changing those passwords.
Using the same password across multiple services creates an additional risk if credentials are ever exposed.
The UK’s National Cyber Security Centre recommends using strong, separate passwords or passkeys and enabling two-step verification where available.
Watch Out for Follow-Up Scams
The biggest risk for customers may come after the original incident.
If criminals have obtained names and contact details, they could potentially use that information to make future phishing messages appear more convincing.
Customers should be suspicious of emails, text messages or social media messages claiming to be from ASOS.
Do not provide passwords, bank details or security codes in response to unexpected messages.
ASOS also warns customers about scammers who impersonate the company through social media, WhatsApp, fake websites and unofficial email accounts.
Monitor Your Accounts
Customers should check their ASOS account for unusual activity.
Look for unexpected changes to account details, unfamiliar orders or other activity that was not authorised.
If you notice an unauthorised payment, contact your bank immediately.
What If You Already Clicked?
If you clicked the link but did not enter any information or download anything, the UK’s National Cyber Security Centre says it is unlikely that further action will be necessary. However, users should remain alert for suspicious activity.
If you provided banking or card information, contact your bank immediately.
If you downloaded software or followed instructions to install something, run a full antivirus scan on your device.
ASOS Continues Investigation
ASOS says its website and app remain available and that customers can continue shopping.
The company has restricted access to the notification platforms involved and is working with specialist advisers and relevant authorities.
For now, the safest approach is to ignore suspicious messages, avoid unknown links and rely only on official ASOS updates.
Customers should also remain particularly cautious of follow-up phishing attempts as the investigation continues.