ASOS acknowledged a cyberattack after an unauthorised notification was sent to customers on 6 October. The British retailer said it was investigating activity involving third-party communication platforms and had restricted access to its notification systems. ASOS
Which information might be affected?
According to that statement, names and contact details may have been accessed. ASOS did not believe passwords or payment-card details were affected. That initial assessment does not mean the investigation is complete. ASOS
Snowflake: separating the threat from the evidence
ITPro documented a message claiming that a Snowflake instance had been compromised and threatening to release information. The outlet also reported a Snowflake spokesperson’s response: its investigation had, at that point, found no compromise of the platform and was continuing. ITPro
In its 7 October follow-up, Infosecurity Magazine reported the assessment of Anastasia Tikhonova, Group-IB’s head of threat research: she had found no evidence establishing that the group held customer data. That assessment limits what is established about the data; it does not negate the attack on the communication channel. Infosecurity Magazine
Why this matters for communication
The case offers a way to examine an everyday expectation: recognising a company’s app may make us trust what appears on screen. REDES’ editorial recommendation is to check the content of an alert too, particularly when it demands immediate action or asks you to open a link.
A business needs to be able to guide the public while it investigates. The NCSC’s incident-response guidance recommends preparing alternative channels, assigning responsibilities and communicating clearly, accurately and promptly, without speculation. NCSC: communications strategy
Applied to this case, each update would benefit from distinguishing what is known, what remains under investigation and what customers should do. This is an editorial recommendation for communicating during an investigation.
What to do if you are a customer
The NCSC advises taking precautions even if you did not receive the notification. It recommends avoiding suspicious links in alerts, emails and messages, and watching for subsequent scams. It also advises securing accounts with passkeys or unique passwords and two-step verification, where available. NCSC: customer advice
As a practical way to follow that advice, check updates through an official address you already know. If a message asks you to pay, disclose a password or provide an access code, verify the request through an independent channel before responding. A brand name alone does not authenticate an instruction.
Trust also needs explanations
For REDES, the communications lesson is that a useful update should help readers decide what to do without overstating what is known. Being clear about the limits of the evidence makes it possible to warn people without presenting a threat as an established fact. Accuracy is also part of caring for the public.
Sources
- ASOS · Update regarding cyber incident · 6 October 2026
- NCSC · Incident affecting ASOS customers · 6 October 2026
- ITPro · Ross Kelly · ASOS notifications and Snowflake response · 6 October 2026
- NCSC · Prepare to make critical decisions · Communications strategy · 1 October 2026
- The Independent · Andrew Griffin · Why was Asos hacked and who did it? · 7 October 2026
- Infosecurity Magazine · Kevin Poireault · Follow-up on the ASOS incident · 7 October 2026