ASOS cites cyber cover as hackers take breach straight to customers
Hackers used the retailer's own app to take the attack straight to customers, and its insurance disclosure has raised questions of its own
ASOS cites cyber cover as hackers take breach straight to customers
CYBER
By Bryony Garlick
07 Oct 2026

At around 10am on Tuesday 6 October, ASOS app users received a push notification titled "ASOS HACKED". Addressed to the online fashion retailer's data protection officer and IT team, the message claimed the attackers had "fully compromised the Snowflake instance" and threatened to leak data unless the company engaged with them.

By the afternoon, ASOS had confirmed in a London Stock Exchange (LSE) announcement that it was investigating unauthorised activity involving third-party platforms it uses to communicate with customers. Names and contact details may have been accessed, it said, but it did not believe payment card information or account passwords had been affected, and its website and app were operating normally. The attackers have offered no evidence to support their claims, and ASOS's statement did not name the platform involved or mention Snowflake.

But it did mention insurance. ASOS said it holds cyber security insurance with a large global provider, including business continuity cover, and that it was too early to quantify any impact on trading. Its shares fell as much as 15% during the day, according to Bloomberg, before closing roughly 10% lower.

The disclosure invites comparison with Marks & Spencer (M&S), hit by one of a wave of targeted attacks on major UK retailers in 2025. M&S received a £100m insurance payout after its attack, against £324m in lost sales.

Insurance as reassurance

Ed Ventham, co-founder and director of cyber insurance broker Assured, said it was notable that ASOS specifically referenced its insurance, and wondered whether it was a response to the sharp fall in its share price.

"What choices do they have other than to just say, by the way, we've got insurance in place? Insurance isn't going to stop the breach necessarily. It's almost saying, if there is a ransom to be demanded, then potentially they've got insurance to pay for it," he said.

He added that he did not know whether a ransom had been demanded, and that with no operational impact disclosed, "it feels like a privacy event".

Straight to customers

Ventham said the speed of the attack, and its direct impact on retail customers, was what stood out. "Usually business gets attacked and they get warned of what might happen, and then they have a time period in which to respond. This is just going straight to the public," he said.

ASOS emailed customers that evening, apologising for the unauthorised notification and asking them not to engage with the link it contained.

What else the attackers reached is the bigger question. Luke Fardell, lead cyber analyst at Tokio Marine Kiln, said incidents of this kind can point to access beyond a single database.

"In some cases, this type of activity may suggest an attacker has gained access to multiple systems rather than a single database. For example, a customer communications platform is usually on a separate system to a cloud data platform such as Snowflake, so organisations need to understand not only what data may have been exposed, but also what other parts of their technology ecosystem could be affected," he said.

The reverse is also possible. Fardell said an attacker could gain access to an app development platform and push a notification out without having broader access to sensitive data, a distinction that will shape the scale of any loss.

ASOS has said it restricted access to the notification platforms immediately and is working with specialist advisers and all relevant authorities, but has not said whether any systems were affected beyond those it uses to contact customers.

More broadly, Fardell said many of the incidents the insurer sees originate from compromised credentials, third-party service providers or shared accounts.

"Maintaining complete control and security becomes increasingly challenging as more people, suppliers and applications require access to large data environments," he said. He said a single compromised account, combined with credential theft or multi-factor authentication bypass, could lead to significant operational and reputational consequences.

With ASOS yet to confirm what, if anything, was taken, the incident adds weight to underwriters' questions on third-party access, shared accounts and credentials, and on how quickly a policyholder can respond when an attacker controls the narrative from the first minute.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.