When ASOS confirmed a suspected cyberattack, the detail that separated it from a standard consumer data story was this: the company publicly disclosed it holds cybersecurity insurance with a large global provider while the investigation was still open.
That single disclosure reframes the story for brokers. The question is no longer whether ASOS is insured. It is whether the policy responds to what actually happened.
Customers in Australia, the UK, and elsewhere received an unauthorised push notification through the ASOS app at around 8pm AEST on Tuesday. The message read: “ASOS hacked. Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
ASOS confirmed the notification was sent without authorisation. Basic personal information, including names and contact details, may have been accessed, the company said. Payment card details and account passwords are not believed to have been affected. The app and website continued to operate normally throughout.
ASOS told Nine it “took immediate action to restrict access to the notification platforms” and is working with internal and external advisers, as well as relevant authorities. Cloud storage provider Snowflake said its own investigation found no compromise of its platform.
The company’s shares fell by as much as 15% on the London Stock Exchange on Tuesday. ASOS told shareholders it was “too early to quantify any potential impact on trading.”
Read next: Queensland’s $809,000 vendor breach tests how far cyber cover reaches
The mechanism here is what brokers need to focus on. Cybersecurity expert Dan Bird from Horizon3 told the BBC that sending a push notification to app users requires access to the company’s notification system, separate from the Snowflake data platform the attackers claimed to have breached. “If both claims hold up, it suggests the attackers got hold of credentials that opened more than one door,” Bird said.
The ASOS incident appears to involve at least two compromised third-party systems. Where the breach started and where the damage was delivered are in different vendor environments.
This sits at the heart of a coverage problem the Australian market has been navigating for some time. MinterEllison’s 2026 Perspectives on Cyber Risk report found 57% of Australian organisations that experienced a cyber incident in the past 12 months were hit through a supplier or vendor.
The notification specifically cited Snowflake, the cloud data storage platform previously linked to breaches at Ticketmaster, Live Nation, Santander Bank, and AT&T.
Joerg Schmitz, cyber risk quantification and analytics leader for APAC at Aon, put it plainly in the firm’s 2025 Cyber Risk Report, published directly on Aon’s Australia website. “The most lucrative attacks are those that can be scaled across multiple targets through a single compromised supplier. This is a wake-up call for Australian businesses to reassess how they manage third-party risk,” Schmitz said.
The data supports that concern. BlueVoyant’s 2025 State of Supply Chain Defense report found 99% of Australian organisations surveyed experienced negative impacts from a supply chain breach in the past year. Only 30% had established or optimised third-party risk management programs, among the lowest rates globally, while 95% plan to grow their third-party vendor ecosystems in the next 12 months – outpacing their ability to monitor or remediate vendor-related risks.
Australian businesses with local customers fall within the scope of the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in Australia in 2025, the highest figure since mandatory reporting began in 2018 and an 8% increase on 2024, with 716 attributed to malicious or criminal activity.
Australian Privacy Commissioner Carly Kind said the threat to Australian businesses was “substantial and rising year on year.”
Beyond notification obligations, financial penalties for inadequate cyber controls are now a reality. In February 2026, the Federal Court ordered FIIG Securities to pay $2.5 million in civil penalties following an Australian Securities and Investments Commission (ASIC) enforcement action for cybersecurity failures, the first time such penalties had been imposed under general Australian Financial Services licence obligations, according to ASIC’s official media release. ASIC deputy chair Sarah Court said “entities that fail to maintain proper cyber security controls risk regulatory action by ASIC and exposure to malicious exploitation.”
For brokers, that precedent changes the policy scope conversation at renewal. A client whose cover does not clearly extend to third-party vendor environments is not just underinsured; they are carrying unpriced regulatory exposure.
Read next: AI breach puts cyber insurance notification rules under scrutiny
Dray Agha from Huntress described the approach to The Guardian as “clear public extortion,” noting that pushing a ransom demand directly to consumer devices was designed to force a rapid response from the business.
Charlotte Wilson from Check Point told the BBC: “If confirmed, this is a deeply serious attack because the hackers appear to have done something particularly brazen: turned ASOS’s own app into their ransom note.”
Using a company’s own communications infrastructure to deliver a public extortion message raises a specific question for consumer-facing clients: do crisis communications coverage or reputational harm provisions respond before a formal breach has been confirmed? That depends on policy wording, and it is worth checking before an incident creates urgency.
NordVPN chief technology officer Marijus Briedis also flagged follow-on risk for customers: “Criminals may exploit the publicity by sending emails and texts claiming to be from ASOS, perhaps asking customers to reset a password, confirm payment details, check an order, or claim a refund.”
ASOS has 16.4 million active customers globally and employs approximately 2,800 staff, according to Sky News UK. The investigation remains ongoing.