A British online fashion giant known for its popularity with Aussies has confirmed it has suffered a data breach, with ‘basic personal information’ being compromised.
ASOS confirmed hackers may have accessed the information after customers received a mobile notification at about 8pm AEST on Tuesday threatening to leak data.
‘Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it,’ the notification read.
Snowflake is a cloud-based data platform which allows businesses to store data, while an ‘instance’ is a dedicated private environment for a company, housing its data, operations and internal processes independently from other businesses.
In a statement issued after the ‘unauthorised’ notification was sent, ASOS said that it did not believe ‘payment card details or passwords were impacted’.
‘We took immediate action to restrict access to the notification platforms and are working with our internal and external specialist advisers as well as all relevant authorities,’ it said.
The number of Aussie customers affected is not known at this stage, but the breach could have significant implications for ASOS, which has more than 16 million active customers worldwide and counts Australia among its largest overseas markets.
Many Aussies weren’t sure what the notification meant while others said they would boycott the company.

A British online fashion giant known for its popularity with Aussies has confirmed it has suffered a data breach, with ‘basic personal information’ being compromised
‘Took me a minute to realise that ‘ASOS HACKED’ wasn’t just some new campaign they were running,’ one said.
‘Pretty sick of these big companies not keeping customers data secure and then when there is a breach, failing to notify customers. I won’t be shopping with ASOS again,’ a second said.
The Telegraph reported that the hackers had demanded a ransom payment from ASOS in exchange for deleting customer information.
It quoted a text from messaging app Telegram, saying: ‘Our message is clear, and simple to recognise. The organisation must contact us or we will leak it [customers’ data], that is what we said. The two-week period is intended for them to make contact, they know what happened.’
Cyber security experts urged any customers potentially caught up in the data breach to remain on high alert.
‘Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order or claim a refund,’ chief technology officer at NordVPN Marijus Briedis said.
‘What customers should be particularly alert to now is what happens next.
‘High-profile cyber incidents create ideal conditions for phishing attacks.’
ASOS confirmed hackers may have accessed the information after customers received a mobile notification at about 8pm AEST on Tuesday threatening to leak data
Despite the worrying developments, customers were able to continue using the retailer’s website and app as normal.
‘Customer trust is incredibly important to us, and if the situation changes, an update will be provided as appropriate,’ an ASOS spokesman said.
More to come.