What experts are saying about the ASOS hack – immediate lessons for ASOS customers and all businesses

In one of the more unusual hacks in memory, ASOS discovered that it had been hacked this morning via an app notification. “Dear ASOS DPD and IT,” it read, “we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”

Customers are obviously concerned, but the company has gone into silent mode. For example, I checked its main website and Facebook page and there was nothing to indicate any problems. Mind you, the last Facebook post was way back in March.

What I have received, entirely unsolicited, are responses from experts with their hot takes on this attack….

Expert reaction to ASOS app attack

“For cyber attacks, 2025 was brutal. 2026 has arguably been worse. Attackers now deploy AI at a speed defenders simply haven’t matched. It’s an asymmetry that widens by the month. Defenders have been slow to adopt stronger authentication, which is like failing to fit better locks on the doors. The attackers take advantage of this. Passwordless systems matter more than ever, but the difficulty of using passkeys in centralised enterprise environments leaves gaps everywhere.

“Ransomware payouts climb, attack surfaces expand, and defenders can’t keep pace. Without coordinated vendor collaboration, the curve bends in the wrong direction.”

Jason Soroko, Senior Fellow at Sectigo (a certificate management company)

What cybersecurity companies are saying

“Some [British businesses are improving cyber resilience], and some are still kidding themselves. The businesses that are improving have stopped chasing best-in-class quadrant rankings and started asking a more practical question: can we mostly recover should something happen? Don’t forget that no business is too small to target.

“Cyber defence and resilience isn’t about having every feature. It’s about being 80% covered and knowing that when something gets through, you can remediate fast. The number of organisations that are still fully patched but have no robust backup capability is staggering.

“It’s like at home when you put your keys down. If you know where everything is, you’ll find them, but if there’s a problem, you’re running around looking for the keys to answer the door. You can do everything right on prevention and still have nothing to roll back to. So then your recovery time won’t be related to a technology problem, but rather an operational discipline problem.”

Spencer Starkey, Executive VP EMEA, SonicWall (cybersecurity specialist)

“It’s too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant. ASOS uses Simon AI for marketing, which runs on Snowflake, making the connection indirect. Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status. That’s valuable profiling data, though the connection alone doesn’t establish what attackers could actually access.”

Pieter Arntz, Senior Malware Intelligence Researcher at Malwarebytes.

Logicalis UKI full response

And here’s an even more in-depth response from James Gillies, Head of Cybersecurity at Logicalis UK&I:

“We still don’t know exactly what has happened at ASOS, so it’s important not to jump to conclusions. But reports that an apparent extortion message intended for the company’s data protection and IT teams has instead been sent directly to customers through the ASOS app are concerning. This raises obvious questions about what access the attackers may have gained and whether that access extends beyond the system they claim to have compromised.

“This is where visibility really matters. Most businesses have a complicated mix of cloud services, SaaS applications, endpoints and third parties, and an attacker won’t necessarily stay in one place. Security teams need to be able to see activity across that environment and piece together what is happening quickly.

Our recent research found that 65% of organisations don’t have fully integrated and automated security telemetry, and 64% don’t have mature 24/7 security operations. Those are significant gaps. An alert on its own doesn’t tell you the whole story. You need the context around it, and people who can investigate and respond. The longer that takes, the more time an attacker potentially has inside the environment.

AI is shortening the time between vulnerabilities being identified and exploited, putting even more pressure on businesses to spot unusual activity early and understand what it means, particularly for retailers, where so much of the customer relationship is digital and the consequences of an incident can escalate quickly.

The answer isn’t simply to add more security tools. Businesses need to know what they have, where their critical assets are and who has access to them. They also need their security systems to work together, with the right people in place to investigate and respond when something happens. You have to assume attackers will keep looking for a way in. The real test is how quickly you know they’re there. Time is the attacker’s advantage: every minute they remain undetected gives them more opportunity to move through systems, access data and increase the damage!”

Distilled advice from experts

So, what’s the easy takeaway from our experts?

First, the threats are only increasing. No shock here, but 2025 and 2026 have seen attacks escalate thanks to our good friend AI.

There’s a lesson for businesses: they must focus on recovery. Prioritise robust, tested backup and recovery, as you can’t block all attacks. But you can make sure you recover quickly when they inevitably occure.

Beware your supply chain. While the full scope of this attack remains unclear, third-party connections and tools can expose your data. Know what they know.

Finally, there’s a real need for visibility. Even big enterprises lack the cross-environment visibility and integrated telemetry they need, giving attackers time to move undetected through their systems.

What should ASOS customers do?

For now, the advice is pretty simple. Hold tight. Don’t click on links in this notification or anything similar, and instead look out for updates on Asos’s website and social media.

Also, be very careful of emails offering refunds. These might come from opportunistic scammers, knowing full well that Asos customers are worried. As a general rule, be very aware of the links you’re clicking on.

This is also a great reminder for everyone to use different passwords for different services. Password managers are your friend.

Finally, just keep an extra wary eye on your online accounts to make sure no odd payments have gone through.

About The Author

Avatar photo
Tim Danton

Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.