Technology·News & analysis
ASOS app users get an 'ASOS HACKED' alert as attackers claim a Snowflake breach
A push notification from the ASOS app told the retailer's data protection and IT teams that hackers had 'fully compromised' its Snowflake data and would leak it. ASOS shares fell about 10%.

Tide
Ripple
Sci-fi
1/10
Reality
Shipping
The ransom note arrived as a push notification.How we rate
Attackers used the ASOS shopping app's own push notifications to send customers a message claiming they had stolen data from the retailer's Snowflake system and would leak it.
ASOS has about 17 million active customers, and its shares fell about 10%. Even before anyone knows whether data was taken, a hijacked app alert shows how a breach can reach customers' phones directly.
What to know
- ASOS app users in several countries got a push notification titled 'ASOS HACKED' on Tuesday morning, addressed to the retailer's data protection officer and IT team.
- The message claimed attackers had 'fully compromised the Snowflake instance' and threatened to leak data unless ASOS engaged with them via a Telegram link.
- ASOS is investigating. It's not yet clear how the alert was sent, whether data was taken, or how many customers are affected.
- ASOS shares fell about 10% in London, and Snowflake shares dropped about 3% in premarket trading.
ASOS shoppers got an unusual message from the fashion retailer's app on Tuesday morning: a ransom demand.
Users received a push notification titled "ASOS HACKED", in what appears to be an attempt by attackers to contact the company's data protection and IT teams, City AM reports.
"Dear ASOS DPO and IT, we have fully compromised the Snowflake instance," the message read. "Engage with us, or we will leak it." It included a link to a Telegram chat.
What happened?
The alert: the notification went to people who have the ASOS app installed. DPO refers to a company's data protection officer, the person responsible for keeping customer information safe, HuffPost UK explains.
When: posts about it began appearing around 10am UK time on Tuesday, October 6, according to HuffPost UK. Downdetector showed problems may have started just before then. LADbible reports about 500 reports about the website and app came in at 9:41am.
Where: reports came from users in several countries, including the UK, US, Germany and Australia, City AM says.
The attackers' claim: in a message on the Telegram channel, a user named "Xuanye Group" said customers' payment information had not been affected. "That is all for now," the apparent hackers wrote, according to City AM.
What's confirmed so far?
Very little.
ASOS is understood to be investigating whether any hack took place, City AM reports. It's not yet clear:
- how the attackers managed to send a notification through the ASOS app;
- whether ASOS's Snowflake systems were compromised as claimed;
- how many customers may have been affected.
ASOS's chatbot told users the company is "currently investigating" the notification, Sky News reported, according to HuffPost UK. A customer service representative added: "We don't have any further information to share at this stage, but we'll provide an update as soon as we know more." That isn't an official statement from the retailer.
As of HuffPost UK's report, ASOS hadn't posted an update on its website or social media. Several outlets said ASOS had been approached for comment.
What is Snowflake, and why does it matter here?
The platform: Snowflake is a cloud data platform used by many companies, including OpenAI, HuffPost UK notes. City AM says ASOS uses it to process data like clothing sizes and body measurements, and that the platform also lets the user send notifications to clients' phones.
The marketing link: Pieter Arntz, senior malware intelligence researcher at Malwarebytes, said ASOS uses Simon AI for marketing, which runs on Snowflake, "making the connection indirect."
"Any exposure could reveal a detailed customer picture, from browsing and buying habits to location and loyalty status," Arntz said. "That's valuable profiling data, though the connection alone doesn't establish what attackers could actually access."
"It's too early to say how much ASOS customer data attackers could get their hands on, but the potential scope is significant," he added.
'Brazen and threatening'
Security experts were struck by how the threat was delivered.
"The attackers aren't simply claiming to have breached ASOS – they're publicly telling the company to engage with them or they will leak what they say they have obtained," said Marijus Briedis, chief technology officer at NordVPN, according to City AM. He called the message "unusually brazen and threatening."
"What makes it even more concerning is how that threat appears to have been delivered," Briedis said. "A message apparently written for ASOS's data protection and IT teams has instead been pushed directly to customers through the company's own app notification system."
Kamran Bahdur, CIO at FLR Spectron, said the message "should be taken seriously and treated as a potential extortion attempt until we've verified the facts," HuffPost UK reports. He said the priority is to check for unauthorized access, review Snowflake audit and authentication logs, and assess any data exposure.
"Any decision on engaging with the threat actor should be made with input from legal, regulatory and law enforcement partners," Bahdur added. "It's also important that personnel avoid direct engagement with the threat actor outside of an agreed response strategy."
How did customers react?
Many were rattled. "Anyone else just get a notification from iOS ASOS UK with a message 'ASOS HACKED: We've taken over the Snowflake instance…'" one user wrote on X. Commenters under that post said they were "scared" and that it looked "pretty bad," HuffPost UK reports.
Others took it in stride. "Whilst ASOS has been hacked can the hacker give us a discount code please and thank u," one person wrote, according to LADbible. Another said: "Hackers sending ransom notes via push notification is diabolical. Long day for ASOS."
Market fallout
ASOS: shares in the London-listed retailer fell by as much as 10% to 439p, City AM reports. HuffPost UK put the drop at 12.5% since reports of the apparent hack broke.
Snowflake: shares fell about 3% in premarket trading in the US, Seeking Alpha reports. Snowflake didn't immediately respond to its request for comment.
Bad timing: ASOS has about 17 million active customers in more than 150 countries and reported revenue of about £2.5 billion in 2025, according to City AM. Its shares were up more than 50% this year before Tuesday, and last month it raised its pre-tax earnings target to £150 million to £180 million.
A turnaround interrupted: ASOS has been trying to revive its fortunes after several difficult years for online fashion. Chief executive José Antonio Ramos Calamonte had been making progress, City AM notes, and the company had cited "materially improved profitability" when it raised its earnings target.
What does 'instance' mean?
In tech terms, an "instance" is a specific running copy of a piece of software, HuffPost UK explains. So the attackers are claiming access to ASOS's own Snowflake environment, not to Snowflake as a whole.
That distinction matters. Malwarebytes' Arntz described ASOS's connection to Snowflake as indirect, through its marketing software, and so far the only claim of a breach comes from the attackers themselves.
What happens next?
If ASOS confirms personal data was compromised, it may have to report it. Under UK data protection rules, organizations generally have 72 hours to notify the Information Commissioner's Office after becoming aware of a personal data breach that poses a risk to people's rights and freedoms, City AM notes. Affected people must also be told without undue delay if a breach is likely to pose a high risk.
British retailers have been hit by several cyberattacks in recent years, with Marks & Spencer, Co-op and Harrods among them, City AM notes.
What it means for you
- If you got the alert: don't tap the notification or the link in it. Experts advised against clicking either, HuffPost UK reports.
- If you shop at ASOS: change your password to a long, unique one, turn on two-factor authentication where possible and back up important data, cybersecurity expert Junade Ali told The Independent.
- Watch for scams: "Be wary of scammers who may attempt to use any personal data for scams," Ali said. Treat unexpected emails or texts about your ASOS account with suspicion.
The bottom line
Attackers claiming to have stolen data from ASOS's Snowflake system sent their ransom demand straight to customers through the ASOS app. ASOS is investigating, nothing about the breach is confirmed yet, and the retailer's shares fell about 10%. Customers should avoid the link, update their passwords and watch for scams.
Key facts
- When
- Tuesday morning, October 6, UK time
- Claimed target
- ASOS's Snowflake instance
- ASOS customers
- About 17 million active, in 150+ countries
- Share move
- ASOS down about 10%, Snowflake down about 3% premarket
- Payment data
- Not affected, the apparent hackers claimed
Got questions?
Quick answers, plain wordsWhat did the ASOS notification say?
Titled 'ASOS HACKED', it read: 'Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it.' It included a link to a Telegram chat.
Was ASOS actually hacked?
Not confirmed yet. ASOS is understood to be investigating whether a hack took place, City AM reports. It's unclear how the attackers sent the notification and whether its Snowflake systems were compromised as claimed.
What is Snowflake?
A cloud data platform used by many companies, including OpenAI, HuffPost UK notes. City AM says ASOS uses it to process data like clothing sizes and body measurements, and that the platform can also send notifications to customers' phones.
Was my payment information stolen?
In a Telegram message, a user named 'Xuanye Group' claimed customers' payment information was not affected, City AM reports. That claim comes from the apparent attackers and hasn't been verified.
What data could be at risk?
Malwarebytes researcher Pieter Arntz said ASOS uses Simon AI for marketing, which runs on Snowflake. Any exposure could reveal browsing and buying habits, location and loyalty status, he said, though the connection alone doesn't show what attackers could access.
Should I click the link in the notification?
No. Experts advised against clicking the notification or the link it contains, HuffPost UK reports.
What should ASOS customers do?
Use long, unique, randomly generated passwords, turn on two-factor authentication where possible, and be wary of scammers who may use personal data, cybersecurity expert Junade Ali told The Independent, as reported by HuffPost UK.
Does ASOS have to report the breach?
If ASOS confirms personal data was compromised, UK rules generally require organizations to notify the Information Commissioner's Office within 72 hours of becoming aware of a breach that poses a risk to people, City AM reports.
How did the markets react?
ASOS shares fell by as much as 10% to 439p, City AM reports, while HuffPost UK put the drop at 12.5%. Snowflake shares fell about 3% in premarket trading, according to Seeking Alpha.
SourcesCity AM
Topics and tagsCybersecurity, asos, snowflake, data breach
Related stories

FBI drops an Accenture contractor after a missed patch exposed staff data
A senior FBI official says a contractor failed to apply a security patch to a system it managed. Sources say it was Oracle's PeopleSoft and the contractor was Accenture, tying it to last month's ShinyHunters breach.

Denmark's national ID register breached, exposing 8.8 million people's CPR numbers
Unknown attackers abused a private company's legal access to Denmark's Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.

A Pentagon records system was breached for 9 months before anyone noticed
The Defense Manpower Data Center disclosed that unauthorized users accessed unencrypted personal data on 2.76 million living and 294,000 deceased people between October 2025 and July 2026.
More in brief
- The Emmys are leaving broadcast TV for Prime Video, and they'll stream free worldwideOct 6
- Paramount closes its $110B Warner Bros. Discovery deal, creating SkydanceOct 6
- Mistral Large 4 'Le Chonk' is a 1-trillion-parameter open model built for cyber defenseOct 6
- Fusion startup Type One Energy raises $200M to build a power plant by 2034Oct 6
- Qualcomm will license Huawei's patents, a reversal 25 years in the makingOct 6
- Google signs a deal to squeeze 890 MW more out of Constellation's nuclear plantsOct 6