The online fashion retailer sent a push notification to users on Tuesday morning that appeared to originate from hackers attempting to extort the company. The message read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."
Asos later issued emails to customers apologising for the "unauthorised push notification" and urged recipients not to click on any links within the message. The company said it had taken immediate action to restrict the suspected hackers' access and was working with advisers and relevant authorities on next steps.
In a subsequent update on Tuesday evening, Asos told customers that the incident may have involved access to "basic personal information including name and contact details." The company stated that it did not believe payment-card information or account passwords had been impacted.
Data storage company Snowflake told the BBC its own investigations had found no compromise of its platform.
Security experts recommend that users who received the notification change their Asos password if they use it elsewhere, enable two-factor authentication where available, and remain vigilant against phishing attempts that may follow the breach.