Summary

Have you been affected?

  1. Asos says it took 'immediate action' to restrict access to notification platformspublished at 15:26 BST

    We can now bring you more from the Asos statement.

    The company says it is investigating the "unauthorised activity involving third-party platforms that we use to communicate with customers".

    Asos also says it took "immediate action to restrict access to the notification platforms" and is working with internal and external advisers, as well as "all relevant authorities".

    It says its website and app are operating "as normal, with no current disruption" to operations.

    "Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate," it says.

    The company adds that it has cyber-security insurance, and says it is "too early to quantify any potential impact on trading".

  2. Asos: 'Basic personal information' may have been accessedpublished at 15:24 BST
    Breaking

    Asos has just released an update following the cyber incident.

    It says an "an unauthorised customer notification" was sent to customers at around 10:00 BST today.

    "Basic personal information including name and contact details may have been accessed," the statement says.

    It adds: "We do not believe that payment-card information or account passwords, were impacted."

    We will bring you more on this shortly.

  3. What experts say after 'really unusual' Asos incidentpublished at 15:05 BST

    An illustration with a laptop and mobile phone shows the website of online fashion retailer ASOSImage source, Getty Images

    We've been hearing from experts over the past few hours after Asos app users received a pop-up notification that appears to have been sent by hackers. Here's what they've said:

    • Reflecting on how worried Asos customers should be, the BBC's Shiona McCallum says there's currently no confirmation that customer information has been stolen
    • Cybersecurity expert Jen Ellis says it is possible any attackers were trying to "apply pressure" to Asos rather than target users
    • It could still be worth taking precautions, though. Another cybersecurity expert Charlotte Wilson suggests changing your password, including across other sites where it might be the same as your Asos one, and being "super cautious" about scam emails and texts
    • We've also shared a list of advice - from avoiding clicking on any links in the hack notification to keeping an eye on your online transactions for anything unusual
    • The BBC's Joe Tidy says it is a "bit surprising" we haven't heard anything from Asos so far - and characterises the whole incident as "really unusual" as cyber-attacks usually happen in private
    • It could go down in cyber-attack history as a really significant moment, he says, calling it a "very aggressive move" to target the company so publicly
  4. Asos 'legally obligated' to inform customers if data has been breached, says consumer rights expertpublished at 14:39 BST

    Kat Cereda looks at a webcam while sitting in an office cubicle.

    A consumer rights expert has said it is still unclear whether hackers have access to any customer data from Asos, given the organisation not yet commented on the situation.

    Kat Cereda from Which? tells BBC News that under UK data protection law, customers have a right to be informed promptly if a breach has put their personal data at high risk.

    She says: "Asos is legally obligated to inform you without any undue delay, explain the consequences and outline what steps they are going to be taking to protect you."

    Cereda advises customers to change their passwords immediately, replacing them with strong alternatives consisting of numbers symbols and a mix of upper and lower cases characters.

    The consumer rights expert also says to hang up on calls from individuals they fear may be posing as Asos or another organisation, telling them to contact the organisation themselves afterwards through separate means.

  5. 'Poor from Asos on all fronts,' says customerpublished at 14:19 BST

    Alex Emery
    Your Voice

    A headshot of Erin smiling in front of a beige wallImage source, Erin

    We've been hearing from more Asos customers about the breach.

    "My main concern is that my information, such as bank information, home address, telephone number, has been compromised," says Erin, a student at the University of Sheffield.

    "The fact Asos have not publicly stated they are investigating, or have not offered any information on how to stay safe, is even more concerning," she adds.

    Erin says that while her friends have expressed similar concerns about a potential data leak, her sister did not receive the notification on the Asos app.

    "So the question is what is the extent? Are all customers affected even if they didn’t get the notification?

    “It’s poor from Asos on all fronts.”

    A purple graphic saying Your Voice on it in large white writing
  6. Snowflake 'hoovers' data from sources, says cyber security expertpublished at 13:56 BST

    Jen Ellis speaks from a webcam in what appears to be her living room.

    A cyber security expert says it is "virtually unheard of" for hackers to use pop-up notifications in this way, adding that the apparent attackers may be trying to "apply pressure" on Asos rather than target its users.

    Jen Ellis tells BBC News the data storage company Snowflake, which is referenced in the pop-up message, is a platform that "hoovers" data from multiple sources for analysis and performing various capabilities.

    She adds an organisation like Asos is "enormous" and has data about buying trends from customers around the world.

    "For an attacker having access to a system like Snowflake, it's a very exciting thing because that data is gold for them. It's money basically just sitting there for them," Ellis adds.

    As a reminder, Asos and Snowflake are yet to comment on the incident.

  7. 'At first I thought it was an ad or a fun promotion'published at 13:38 BST

    Alex Emery
    Your Voice

    A photo of Jodie with her hair down and wearing a white jacket.

    Jodie, an analyst from Edinburgh, says she's feeling concerned after clicking the Asos notification that popped up on her phone.

    "At first I thought it was an ad or a fun promotion like ‘ASOS HACKED get 50% off everything for a limited time only’," she says.

    "Then I read the rest of the message which clearly showed that it wasn’t an ad and instead a message to IT.

    "I clicked on it expecting maybe a message within the app itself but nothing came up. The push notification just disappeared and there was no obvious change in the account.

    "It’s concerning if it is a data leak, that my address and other details may be accessed."

    A purple background with white letters spelling "your voice".
  8. National Cyber Security Centre offers Asos assistance, BBC understandspublished at 13:29 BST
    Breaking

    Chris Vallance
    Senior technology reporter

    The BBC understands the National Cyber Security Centre (NCSC) has offered assistance to Asos, after reports that users of its app received a notification apparently sent by hackers.

    The NCSC, part of the UK's intelligence agency GCHQ, provides advice and support for the public, businesses and public sector organisations on how to defend against cyber-attacks and other information security threats.

    It also supports businesses dealing with cyber-incidents and publishes guidance for individuals who believe they have been a victim of a data breach, external.

  9. Company investigating whether notification 'may be a scam' - Asos chatbot agent sayspublished at 13:24 BST

    BBC presenter Pria Rai has also been speaking to the Asos chatbot function on its app.

    She says that after an agent was connected to her chat, they said: "I understand you'd like to know whether the notification is genuine and whether your account may be at risk.

    "I've reviewed the details and it may be a scam, however I've escalated it to our experts who are currently investigating."

    Earlier, our reporter also contacted the chatbot - the agent told her that they are looking into the issue and advised her against clicking any links.

  10. Asos shares down as apparent hack creates risk for companypublished at 13:19 BST

    Michael Race
    Business and economics reporter

    Parcel and boxes bearing the Asos logo in a crate awaiting shippingImage source, Getty Images

    Cyber attacks can spell huge financial implications for companies due to the huge disruption to operations by systems and data being compromised - as well as hackers typically hoping to extort a pay-off.

    Those fears appear to be gathering among investors today, with shares in Asos down almost 10% following the emergence of messages on its app appearing to have been sent by hackers. The company is yet to comment.

    Asos is an online retailer based in the UK and has millions of customers worldwide.

    While popular with influencers and content creators advertising its products, the fashion firm has been struggling from declining sales in recent years and is in the middle of a turnaround plan aimed at returning to profit.

    Ahead of its full-year results, due to be released next month, the company said there were positive signs in its recovery - however, today's news creates risk to that.

    Following a cyber attack last year, M&S's profits were almost wiped out as customers were left unable to buy online from the retailer for months.

    Asos will be hoping this incident will not leave long lasting damage and can be resolved as fast as possible.

  11. Asos breach would add to string of recent retail hackspublished at 13:12 BST

    Liv McMahon
    Technology reporter

    Outside shot of an M&S shop at Westfield Stratford City in East London. Shoppers are walking around carrying bagsImage source, Getty Images
    Image caption,

    Last year, M&S was forced to halt online purchases for several months after a hugely damaging cyber attack

    The Asos incident would appear to be the latest in a string of retail hacks and breaches that have taken place in recent years.

    British brands targeted range from supermarkets like the Co-op and M&S, to carmakers including Jaguar Land Rover – with all reporting heavy sales losses in the aftermath.

    Even luxury fashion retailers such as Gucci, Balenciaga and Alexander McQueen have had customer details stolen in high-profile hacks.

    But few cyber criminals behind such incidents have been quite so public or direct in communicating a successful breach as these apparent hackers have here – and that’s what has really taken aback some experts, as well as our own cyber correspondent Joe Tidy.

  12. What we do and don't know about the Asos hack threatpublished at 13:06 BST

    If you're just joining us, here's a recap of what we know so far about the Asos hacking threat.

    What we know:

    • Late this morning, Asos customers across the UK received a notification from the retailer's app, apparently from hackers
    • The notification said: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it"
    • Snowflake - a data storage company - has been linked to incidents targeting services including Ticketmaster and Santander
    • App users in Australia, Ireland, and France have since reported receiving the alert

    What we still don't know:

    • Who is behind the hacking threat and their motivation
    • Confirmation about whether any customer information has been stolen
    • If Asos is a customer of Snowflake or what data, if any, is stored with the service
    • The scale and seriousness of the breach
  13. Asos alert reported beyond the UKpublished at 12:56 BST

    Shiona McCallum
    Senior technology reporter

    We’re looking into how widely today’s threatening Asos app notification was circulated, with reports now emerging overseas.

    Australian media say app users there received the alert, external. The Journal in Ireland has published a screenshot from an Irish customer, while French technology outlet Numerama says it received the notification itself., external

    Asos is a British retailer with a substantial global footprint. The company says it serves around 17 million customers each year across more than 150 markets.

    The number of people who received the alert remains unknown. We’re trying to establish its reach, how many users received it and whether any customer information was affected.

  14. This could go down in cyber-attack history as a really significant momentpublished at 12:49 BST

    Joe Tidy
    Cyber correspondent

    Picture of a phone screen showing the App Store open on the download page for the Asos appImage source, Getty Images

    We have heard nothing from Asos so far, but expect they could put out a statement soon.

    It's a bit surprising we haven't heard from them already - it would be very unusual if this was the first the company had heard about the hack.

    Usually, cyber-attacks happen in private - they are extortion events between a victim organisation and a cyber crime gang. This allows them time to negotiate a price to pay.

    The kind of thing we've seen today is really unusual.

    It could go down in cyber-attack history as a really significant moment - it's a very aggressive move to try to extort the company so publicly.

    It is possible this is more widespread than just a UK incident. I have been speaking to someone in the US just now who also got the pop-up on her phone.

    In one of the few messages the hacker has posted on its Telegram page since creating it, it says payment information is not affected. Of course, we have to take everything cyber criminals say with a pinch of salt.

  15. Asos customer tells BBC they are 'scared to go into the app'published at 12:37 BST

    A project manager, 23, who wants to remain anonymous, says they are "feeling very confused and scared to go into the app".

    “Is my data safe? Are my bank details at risk?" the person from Canterbury tells the BBC.

    “I don’t know what to do so I have just left it. I won’t click the link so I’m waiting to hear from Asos about what to do.

    “I don’t feel comfortable deleting the app until I know that all my details are safe.”

    A purple banner with white writing saying Your Voice on it
  16. Be 'super cautious' about scam emails and texts, cyber expert tells Asos customerspublished at 12:28 BST

    Charlotte Wilson, head of enterprise at cyber-security firm Check Point, speaks to BBC from her home

    Charlotte Wilson, head of enterprise at cyber-security firm Check Point, tells the BBC there's still "an awful lot" we don't know about the apparent Asos cyber-attack - including the motivation.

    The hackers claim to have gained access to data storage company Snowflake but Wilson says this hasn't yet been confirmed. She adds that experts also aren't in a position to "confirm what [the hackers] have compromised or quite what they've got".

    Asked whether the breach is serious, she says "possibly", although it is also possible the hackers are just trying to create a "big public message and an embarrassment".

    Her advice to Asos customers is not to be "really scared and frightened" - and to change your password, including across other sites where the password is the same as your Asos one.

    She also says you should avoid clicking on the link in the hack notification, and be "super cautious" when it comes to possible scam emails and text messages.

  17. How worried should Asos customers be?published at 12:18 BST

    Shiona McCallum
    Senior technology reporter

    Clearly, getting an alert like this will concern people but, at the moment, there is no confirmation that customer information has been stolen.

    Receiving the notification doesn’t mean your phone has been hacked - the risk will depend on if any information was accessed by the hackers.

    For now, the advice is:

    • Do not click on links in the notification
    • Visit Asos’s official website directly for updates
    • Watch out for emails, texts or calls offering refunds, compensation or help with your account - scammers will exploit this type of incident when they know people are worried
    • Try and use different passwords for your online services
    • Enable two-step verification on email and banking accounts
    • Keep an eye on your online transactions for anything unusual
  18. Asos chatbot says retailer 'aware of notification' and 'investigating'published at 12:11 BST

    Imogen James
    Live reporter

    We're yet to hear an official response from Asos, but in the meantime I've been speaking to the retailer's online chatbot to ask whether I'm safe to use my Asos account after the pop-up message.

    The bot replied: "Thanks for flagging this. We're aware of the notification and are currently investigating."

    It said it had no further information to share, but would provide an update "as soon as we know more".

    Screenshot of BBC journalist speaking to Asos chatbot and agent

    I was then connected to an agent, who told me they understand my concern. They added: "Please don't worry, as we're aware of this issue and it's currently being looked into."

    Screenshot of BBC journalist speaking to Asos chatbot and agent
  19. Snowflake has been the subject of other high profile breaches in recent yearspublished at 11:42 BST

    Joe Tidy
    Cyber correspondent

    The company has been linked to incidents targeting services including Ticketmaster and Santander.

    It is, however, unusual that any potential data breach would be revealed quite so publicly - and for customers to be informed in this manner.

    Most extortions and negotiations by cyber criminals are conducted in private, with hackers hoping their discretion will result in a quiet pay-off.

    Dan Bird, from cyber security firm Horizon3, says the pop-up message apparently sent by the criminals implies their access has gone beyond the Snowflake database.

    "Sending a push notification to Asos's app users would require access to the company's notification system, which is separate from the Snowflake data platform the attackers claim to have compromised," he says.

    "If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door."

  20. What is Snowflake?published at 11:34 BST

    In the pop-up message, thought to have been sent by hackers, users were told the "Snowflake instance" had been "fully compromised".

    Snowflake is a data storage company, whose popular tools have been used by dozens of firms for collecting, analysing and storing data.

    It uses the cloud, so businesses store, manage and analyse their data in the cloud, meaning no large databases are needed on site.

    This means it's easier to share data across different teams.

    Its website says there are 12,062 global customers.