ASOS Cyber Incident: What Happens When a Cyber Attack Becomes Public in Seconds?
At 9:58am on Tuesday 6 October, phones across the UK began lighting up with a notification that nobody expected to receive from the ASOS app. The message was addressed directly to the retailer's Data Protection Officer and IT team: “Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.”
It was followed by a link to a Telegram account.
Within minutes, screenshots were being shared online. News organisations were reporting on the incident. Customers were questioning whether their information was safe. And the ASOS share price was falling.
This wasn't a cyber incident quietly unfolding behind closed doors. It was happening publicly, on customers' phones. And it provides businesses with a powerful example of just how quickly the consequences of a cyber incident can extend far beyond the IT department.
What Happened to ASOS?
At around 10am on 6 October, ASOS customers received an unauthorised push notification through the company's app.
The notification claimed that attackers had “fully compromised” an ASOS Snowflake instance and threatened to leak information unless the company engaged with them. Snowflake is a cloud data platform used by organisations to store, process and analyse large amounts of business data.
The notification itself did not prove that the claim about Snowflake was true. However, ASOS subsequently confirmed that it was investigating unauthorised activity involving third-party platforms used to communicate with customers.
The company said it immediately restricted access to its notification platforms and began working with internal and external specialists and the relevant authorities.
ASOS also confirmed that basic personal information, including names and contact details, may have been accessed. At the time of its statement, the company said it did not believe payment-card information or account passwords had been affected. Its website and app remained operational.
The National Cyber Security Centre has since published guidance about the incident and advised ASOS customers to assume they could be affected, even if they did not personally receive the unauthorised notification.
A Cyber Attack Playing Out in Public
What makes this incident particularly interesting isn't simply the allegation that data had been compromised. It is how the alleged attackers communicated their demand.
Instead of privately contacting the organisation, the message appeared through a communication channel normally used by ASOS to speak directly to its customers.
Cybersecurity experts described this as a form of public extortion: creating pressure on the organisation by making customers, investors and the wider public aware of the situation at almost exactly the same time as the business itself.
Think about the consequences of that.
The IT and security teams need to establish what has happened.
Leadership needs information.
Customers want reassurance.
The media wants answers.
Regulators and authorities may need to become involved.
Meanwhile, screenshots are spreading across social media and investors are reacting.
There is almost no breathing room between technical incident and business crisis.
An 11% Share-Price Fall Shows How Quickly the Impact Spreads
The market reaction was almost immediate. ASOS shares fell by more than 11% on Tuesday morning as reports of the incident emerged. The Guardian reported a fall approaching 12%, while Reuters reported a decline of more than 11% during the initial reaction.
That matters, because one of the biggest misconceptions surrounding cyber security is that the cost of an attack is limited to fixing computers, restoring systems or recovering data. It isn't.
A serious cyber incident can affect reputation, customer confidence, operations, regulatory obligations, suppliers, employees and ultimately the value of the business itself.
ASOS's systems didn't even need to stop operating for consequences to become visible. The company confirmed later that day that its website and app were operating normally, yet the financial and reputational reaction had already begun.
Your Customers Don't Wait for the Investigation
There's another important lesson here. Cyber investigations take time. Customers don't necessarily wait. When someone sees a threat to leak information, their first thought probably isn't about incident-response procedures or forensic analysis. It's much simpler: “Do they have my information?”
That uncertainty has consequences of its own.
It can lead customers to change passwords, remove information, contact the business, scrutinise transactions or become more susceptible to follow-on phishing attacks pretending to offer information about the breach.
That's why communication is such an important part of cyber resilience.
Your organisation needs to know not only how it will contain and investigate an incident, but also who communicates, what they communicate and how quickly they can do it.
Cyber Security Is a Business Risk
This is exactly why Sunrise Technologies continually talks about cyber security as a business issue, not simply an IT issue.
Preventing attacks remains incredibly important. But businesses also need to ask what happens if preventative controls aren't enough.
How quickly could you detect unusual activity?
Would you understand what had been compromised?
Could you contain it?
Could you recover your systems and data?
Who would make the decisions?
Who would communicate with customers?
And what would happen to your business while all of that was taking place?
The ASOS incident demonstrates how quickly those questions can stop being hypothetical. At approximately 9:58am, customers were receiving an unexpected push notification. Within the hour, the company's share price had fallen sharply and the incident was being reported nationally. By the afternoon, ASOS had issued a formal regulatory announcement confirming an investigation into unauthorised activity.
That's how quickly cyber risk can become business risk.
Could Your Business Survive a Cyber Attack?
For most businesses, the important question isn't whether they have the resources of a company like ASOS.
It's whether they are prepared for their own version of this situation.
You might never have millions of customers receiving a push notification. But you could have employees unable to access systems. Customers asking whether their information is safe. A supplier demanding answers. A compromised Microsoft 365 account. A ransomware demand. A critical system unavailable. Or sensitive information appearing somewhere it shouldn't.
The scale may be different. The decisions you need to make aren't.
Good cyber security therefore isn't just about buying security products. It's about understanding your risks, putting appropriate protections in place, monitoring what is happening and having a plan for when something goes wrong.
At Sunrise Technologies, we help businesses take a proactive approach to technology and cyber security, identifying risk before it becomes disruption and helping organisations build greater resilience.
Because when a cyber incident happens, the consequences don't wait for your IT team to finish investigating.
Worried About Your Business's Cyber Security?
If this incident has made you question how prepared your organisation would be for a cyber attack, talk to the Sunrise Technologies team.
We can help you understand your current cyber security position, identify areas of risk and put practical measures in place to better protect your people, systems and data.