What we do - and don't - know about Asos cyber incidentpublished at 16:19 BST
Katie Williams
Live reporter
Asos has just delivered an update after an "unauthorised customer notification" was sent to app users this morning. Here's what we do - and don't - know about the incident.
What we know
- Asos says it is investigating the "unauthorised activity involving third-party platforms that we use to communicate with customers"
- "Basic personal information" like name and contact details may have been accessed, but Asos says it believes payment-card information and passwords weren't impacted
- It comes after some Asos app users received a notification at around 10:00 BST this morning titled: "ASOS HACKED". Although sent to customers, it was addressed to Asos's data protection office and IT team, urging them to "engage with us" or risk a leak
- The BBC understands the National Cyber Security Centre has offered Asos its assistance - the agency supports businesses dealing with cyber-incidents
What we don't know
- Who is behind the notification, what motivated them and how they sent a notification
- Exactly what information the apparent hackers have accessed and whether there is still a risk
- How many people were impacted
- What this means for data storage company Snowflake. The unauthorised Asos notification said hackers had "fully compromised the Snowflake instance", but Snowflake subsequently told the BBC it has found "no compromise of the Snowflake platform" so far
















