Summary

  • Asos says it is "investigating unauthorised activity" after app users received a pop-up message from apparent hackers - here's what we know so far

  • Customers' "basic personal information including name and contact details may have been accessed," the online retailer says, adding it doesn't think payment information or account passwords were impacted

  • The notification - sent earlier - said: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it"

  • Asos customer Lucy told the BBC they have deleted "all my card information, changed my password and address" from the app. Another said she's worried the message may have "affected the integrity of security" of her phone

  • This could go down in cyber-attack history as a really significant moment - it's a very aggressive move to try to extort the company so publicly, says the BBC's Joe Tidy

  • Did you get the notification? Here's what you should do

Have you been affected?

  1. Asos loses almost a tenth of its value on London's stock market amid apparent hackpublished at 17:04 BST

    Archie Mitchell
    Business reporter

    Asos shares tumbled on Tuesday, with the company losing just under a tenth of its value on London’s stock market after being hit by the cyber attack.

    Shares fell 9.56%, with analysts warning it could undermine an ongoing turnaround at the company and risk customer trust.

    Dan Coatsworth, head of markets at investment platform AJ Bell, said Asos will need to “rapidly show it can fix any vulnerabilities in its systems and provide clarity on any related financial hit”.

    He said it was not long ago that Marks & Spencer was “hit for six” by a cyberattack, which had a major impact on its earnings.

    Tuesday’s dip comes after an otherwise positive year for Asos, with its shares still worth more than double what they were in January.

  2. BBC Verify

    Telegram channel linked in Asos message appears to use Chinese translationspublished at 16:54 BST

    By Sam Howarth

    BBC Verify has been looking into channels on the Telegram messaging app that appear to be linked to the push notification sent to Asos users this morning.

    The notification included a link to one Telegram channel which in turn directed users to the “Xuanye Group Channel”. The channel appears to have been created today.

    Its first message began “hello dears” before saying it was a “legitimate channel” and warning users to be wary of impersonation. A second message read: “Regarding ASOS, payment information is not affected.”

    Four hours later, the channel posted a further message saying the Asos app was safe to use and the incident involved customer information. It added the information was “safe on our server” and would not be accessed for a "designated period". We have not been able to confirm this.

    BBC Verify found the Telegram channel and account names used spellings consistent with Chinese pinyin - a system for representing Chinese characters using the Latin alphabet. It is widely used in mainland China.

    The messages also include language that appears to have been translated from Chinese. The “hello dears” greeting resembles the informal Chinese expression 亲们 “qīnmen” which is commonly used online to address a group of people in a warm or familiar way.

    The use of Chinese pinyin and this wording do not, on their own, establish who is behind the accounts or where the group is based.

  3. 'I thought the hack notification was a way of catching customers' attention'published at 16:42 BST

    James Kelly
    Your Voice

    "Initially, I thought it was a promotion or a way of catching customers’ attention for a sale," says Emily from Bristol.

    The 30-year-old says she's worried she may have "affected the integrity of security" of her phone by opening the message.

    "I clicked on it, but when it took me to the app’s home page, I became concerned and wondered whether it could be a way of obtaining customer information," she explains.

    "I’m a regular Asos customer, but this experience may make me a little more cautious about shopping with them in the future."

    Purple banner with the words Your Voice
  4. 'It's about how you recover and communicate to customers,' says retail analyst on cyber attackspublished at 16:29 BST

    Catherine Shuttleworth sits in a colourful office while speaking to her webcam.

    Hacks of today's nature are an "awful thing" to happen to any business and have unfortunately become a part of their lives, a retail analyst has said.

    Catherine Shuttleworth, the chief executive of marketing agency Savvy, says the country needs to think more about how its data and systems are being protected from hackers.

    She also says customers generally understand that such attacks are outside of the brand's control, with many still trusting Marks & Spencer after last year's cyber attack.

    "It's about how you recover from it, it's about how you communicate to your customers and you communicate to your staff," she says.

  5. What we do - and don't - know about Asos cyber incidentpublished at 16:19 BST

    Katie Williams
    Live reporter

    Asos has just delivered an update after an "unauthorised customer notification" was sent to app users this morning. Here's what we do - and don't - know about the incident.

    What we know

    • Asos says it is investigating the "unauthorised activity involving third-party platforms that we use to communicate with customers"
    • "Basic personal information" like name and contact details may have been accessed, but Asos says it believes payment-card information and passwords weren't impacted
    • It comes after some Asos app users received a notification at around 10:00 BST this morning titled: "ASOS HACKED". Although sent to customers, it was addressed to Asos's data protection office and IT team, urging them to "engage with us" or risk a leak

    What we don't know

    • Who is behind the notification, what motivated them and how they sent a notification
    • Exactly what information the apparent hackers have accessed and whether there is still a risk
    • How many people were impacted
    • What this means for data storage company Snowflake. The unauthorised Asos notification said hackers had "fully compromised the Snowflake instance", but Snowflake subsequently told the BBC it has found "no compromise of the Snowflake platform" so far
  6. 'I deleted all my card information, changed my password and address'published at 16:06 BST

    Imogen James
    Live reporter

    I've been speaking to Lucy from Cumbria, who says "it was quite startling" to receive the notification.

    The 21-year-old says she was concerned about "something being compromised" so went onto X to see if other people had received it.

    "I saw a lot of posts about it, with quite a few saying about deleting personal information, so I went on to the app (which was working as normal) to change my details.

    "I deleted all my card information, changed my password and address," she says.

    Lucy also messaged her sister, telling her to do the same as she is a frequent Asos user.

    "Interestingly, my sister hasn’t got the notification so I told her not to click on any notifications she gets from Asos for the time being," she told me. Lucy says her sister also lives in the UK.

    When I asked her if she is now put off by using the app in the future, Lucy says: "I definitely won’t be using it until they know what exactly has been compromised.

    "It will definitely make me more cautious and more likely to buy directly from the retailers that they stock instead."

  7. Asos app has more than 10 million downloads but it's unclear how many received notificationpublished at 15:50 BST

    Joe Tidy
    Cyber correspondent

    It’s still not known how many people received the pop up message but on Google’s Play store it shows that the Android app for the popular fashion and beauty company has been downloaded more than 10 million times.

    Some of those people might not have app notifications turned on of course but it would make sense that millions of people would have - and so are likely to have got the apparent hacker’s message.

    Apple’s Appstore does not show the number of downloads for that version of the app but it does show more than 500,000 reviews, giving us an idea of how popular it is with iPhone users.

    The only people who would know for sure how many people received the pop-up notification is Asos themselves.

  8. 'No compromise of the Snowflake platform', company's communications director sayspublished at 15:41 BST

    In a statement to the BBC, data storage company Snowflake says: "As soon as we became aware of the notification that is currently being reported, we began an investigation.

    "At this time, we can report that we have found no compromise of the Snowflake platform. We take customer privacy and security very seriously," Katherine James, director of Snowflake's Europe, Middle East, and Africa communications team says.

    "The investigation is ongoing and we will provide further updates as soon as more information becomes available."

    As a reminder, in the pop-up notification, the apparent hackers wrote that "we have fully compromised the Snowflake instance".

  9. Asos says it took 'immediate action' to restrict access to notification platformspublished at 15:26 BST

    We can now bring you more from the Asos statement.

    The company says it is investigating the "unauthorised activity involving third-party platforms that we use to communicate with customers".

    Asos also says it took "immediate action to restrict access to the notification platforms" and is working with internal and external advisers, as well as "all relevant authorities".

    It says its website and app are operating "as normal, with no current disruption" to operations.

    "Customer trust is incredibly important to us, and if the situation changes an update will be provided as appropriate," it says.

    The company adds that it has cyber-security insurance, and says it is "too early to quantify any potential impact on trading".

  10. Asos: 'Basic personal information' may have been accessedpublished at 15:24 BST
    Breaking

    Asos has just released an update following the cyber incident.

    It says an "an unauthorised customer notification" was sent to customers at around 10:00 BST today.

    "Basic personal information including name and contact details may have been accessed," the statement says.

    It adds: "We do not believe that payment-card information or account passwords, were impacted."

    We will bring you more on this shortly.

  11. What experts say after 'really unusual' Asos incidentpublished at 15:05 BST

    An illustration with a laptop and mobile phone shows the website of online fashion retailer ASOSImage source, Getty Images

    We've been hearing from experts over the past few hours after Asos app users received a pop-up notification that appears to have been sent by hackers. Here's what they've said:

    • Reflecting on how worried Asos customers should be, the BBC's Shiona McCallum says there's currently no confirmation that customer information has been stolen
    • Cybersecurity expert Jen Ellis says it is possible any attackers were trying to "apply pressure" to Asos rather than target users
    • It could still be worth taking precautions, though. Another cybersecurity expert Charlotte Wilson suggests changing your password, including across other sites where it might be the same as your Asos one, and being "super cautious" about scam emails and texts
    • We've also shared a list of advice - from avoiding clicking on any links in the hack notification to keeping an eye on your online transactions for anything unusual
    • The BBC's Joe Tidy says it is a "bit surprising" we haven't heard anything from Asos so far - and characterises the whole incident as "really unusual" as cyber-attacks usually happen in private
    • It could go down in cyber-attack history as a really significant moment, he says, calling it a "very aggressive move" to target the company so publicly
  12. Asos 'legally obligated' to inform customers if data has been breached, says consumer rights expertpublished at 14:39 BST

    Kat Cereda looks at a webcam while sitting in an office cubicle.

    A consumer rights expert has said it is still unclear whether hackers have access to any customer data from Asos, given the organisation not yet commented on the situation.

    Kat Cereda from Which? tells BBC News that under UK data protection law, customers have a right to be informed promptly if a breach has put their personal data at high risk.

    She says: "Asos is legally obligated to inform you without any undue delay, explain the consequences and outline what steps they are going to be taking to protect you."

    Cereda advises customers to change their passwords immediately, replacing them with strong alternatives consisting of numbers symbols and a mix of upper and lower cases characters.

    The consumer rights expert also says to hang up on calls from individuals they fear may be posing as Asos or another organisation, telling them to contact the organisation themselves afterwards through separate means.

  13. 'Poor from Asos on all fronts,' says customerpublished at 14:19 BST

    Alex Emery
    Your Voice

    A headshot of Erin smiling in front of a beige wallImage source, Erin

    We've been hearing from more Asos customers about the breach.

    "My main concern is that my information, such as bank information, home address, telephone number, has been compromised," says Erin, a student at the University of Sheffield.

    "The fact Asos have not publicly stated they are investigating, or have not offered any information on how to stay safe, is even more concerning," she adds.

    Erin says that while her friends have expressed similar concerns about a potential data leak, her sister did not receive the notification on the Asos app.

    "So the question is what is the extent? Are all customers affected even if they didn’t get the notification?

    “It’s poor from Asos on all fronts.”

    A purple graphic saying Your Voice on it in large white writing
  14. Snowflake 'hoovers' data from sources, says cyber security expertpublished at 13:56 BST

    Jen Ellis speaks from a webcam in what appears to be her living room.

    A cyber security expert says it is "virtually unheard of" for hackers to use pop-up notifications in this way, adding that the apparent attackers may be trying to "apply pressure" on Asos rather than target its users.

    Jen Ellis tells BBC News the data storage company Snowflake, which is referenced in the pop-up message, is a platform that "hoovers" data from multiple sources for analysis and performing various capabilities.

    She adds an organisation like Asos is "enormous" and has data about buying trends from customers around the world.

    "For an attacker having access to a system like Snowflake, it's a very exciting thing because that data is gold for them. It's money basically just sitting there for them," Ellis adds.

    As a reminder, Asos and Snowflake are yet to comment on the incident.

  15. 'At first I thought it was an ad or a fun promotion'published at 13:38 BST

    Alex Emery
    Your Voice

    A photo of Jodie with her hair down and wearing a white jacket.

    Jodie, an analyst from Edinburgh, says she's feeling concerned after clicking the Asos notification that popped up on her phone.

    "At first I thought it was an ad or a fun promotion like ‘ASOS HACKED get 50% off everything for a limited time only’," she says.

    "Then I read the rest of the message which clearly showed that it wasn’t an ad and instead a message to IT.

    "I clicked on it expecting maybe a message within the app itself but nothing came up. The push notification just disappeared and there was no obvious change in the account.

    "It’s concerning if it is a data leak, that my address and other details may be accessed."

    A purple background with white letters spelling "your voice".
  16. National Cyber Security Centre offers Asos assistance, BBC understandspublished at 13:29 BST
    Breaking

    Chris Vallance
    Senior technology reporter

    The BBC understands the National Cyber Security Centre (NCSC) has offered assistance to Asos, after reports that users of its app received a notification apparently sent by hackers.

    The NCSC, part of the UK's intelligence agency GCHQ, provides advice and support for the public, businesses and public sector organisations on how to defend against cyber-attacks and other information security threats.

    It also supports businesses dealing with cyber-incidents and publishes guidance for individuals who believe they have been a victim of a data breach, external.

  17. Company investigating whether notification 'may be a scam' - Asos chatbot agent sayspublished at 13:24 BST

    BBC presenter Pria Rai has also been speaking to the Asos chatbot function on its app.

    She says that after an agent was connected to her chat, they said: "I understand you'd like to know whether the notification is genuine and whether your account may be at risk.

    "I've reviewed the details and it may be a scam, however I've escalated it to our experts who are currently investigating."

    Earlier, our reporter also contacted the chatbot - the agent told her that they are looking into the issue and advised her against clicking any links.

  18. Asos shares down as apparent hack creates risk for companypublished at 13:19 BST

    Michael Race
    Business and economics reporter

    Parcel and boxes bearing the Asos logo in a crate awaiting shippingImage source, Getty Images

    Cyber attacks can spell huge financial implications for companies due to the huge disruption to operations by systems and data being compromised - as well as hackers typically hoping to extort a pay-off.

    Those fears appear to be gathering among investors today, with shares in Asos down almost 10% following the emergence of messages on its app appearing to have been sent by hackers. The company is yet to comment.

    Asos is an online retailer based in the UK and has millions of customers worldwide.

    While popular with influencers and content creators advertising its products, the fashion firm has been struggling from declining sales in recent years and is in the middle of a turnaround plan aimed at returning to profit.

    Ahead of its full-year results, due to be released next month, the company said there were positive signs in its recovery - however, today's news creates risk to that.

    Following a cyber attack last year, M&S's profits were almost wiped out as customers were left unable to buy online from the retailer for months.

    Asos will be hoping this incident will not leave long lasting damage and can be resolved as fast as possible.

  19. Asos breach would add to string of recent retail hackspublished at 13:12 BST

    Liv McMahon
    Technology reporter

    Outside shot of an M&S shop at Westfield Stratford City in East London. Shoppers are walking around carrying bagsImage source, Getty Images
    Image caption,

    Last year, M&S was forced to halt online purchases for several months after a hugely damaging cyber attack

    The Asos incident would appear to be the latest in a string of retail hacks and breaches that have taken place in recent years.

    British brands targeted range from supermarkets like the Co-op and M&S, to carmakers including Jaguar Land Rover – with all reporting heavy sales losses in the aftermath.

    Even luxury fashion retailers such as Gucci, Balenciaga and Alexander McQueen have had customer details stolen in high-profile hacks.

    But few cyber criminals behind such incidents have been quite so public or direct in communicating a successful breach as these apparent hackers have here – and that’s what has really taken aback some experts, as well as our own cyber correspondent Joe Tidy.

  20. What we do and don't know about the Asos hack threatpublished at 13:06 BST

    If you're just joining us, here's a recap of what we know so far about the Asos hacking threat.

    What we know:

    • Late this morning, Asos customers across the UK received a notification from the retailer's app, apparently from hackers
    • The notification said: "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it"
    • Snowflake - a data storage company - has been linked to incidents targeting services including Ticketmaster and Santander
    • App users in Australia, Ireland, and France have since reported receiving the alert

    What we still don't know:

    • Who is behind the hacking threat and their motivation
    • Confirmation about whether any customer information has been stolen
    • If Asos is a customer of Snowflake or what data, if any, is stored with the service
    • The scale and seriousness of the breach