On the morning of Tuesday 6 October 2026, attackers sent a push notification titled "ASOS HACKED" through the official ASOS mobile app to customers' phones. It read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The message linked to a Telegram channel. The hijack itself is not in doubt: the BBC, The Guardian, The Register, Infosecurity Magazine and others have all corroborated it from screenshots and customer reports. The claim that ASOS's Snowflake data platform was breached is a separate matter and remains unverified. At the time of writing, no primary source exists. ASOS has published no breach notice, and no regulator filing or Snowflake advisory has appeared. Reuters and the Financial Times (as cited by The Economic Times) and The Guardian report only that ASOS said it was "aware" of the reports and was investigating. The company has not confirmed a cyberattack or any loss of customer data. ASOS shares fell sharply after the notification. Reported figures range from about 5% in the first 30 minutes (IT Security Guru) to almost 12% (The Guardian, The Register) and 12.5%, or about £70 million in market value (The Independent).
What Happened
- Timing: IT Security Guru puts the notification at about 10:00 BST. It reports that Downdetector logged about 500 problem reports from around 09:40, mostly about the app rather than the website. The Independent also ties the share slide to "around 10am".
- Delivery: The message came through ASOS's legitimate push notification channel, so it looked like an official ASOS alert. It was addressed to ASOS's data protection officer (DPO) and IT team, not to shoppers.
- Reach: Accounts of how far it spread differ. The BBC says "dozens" of people contacted it and describes recipients "across the UK". The Guardian says "thousands" of customers received it. IT Security Guru reports recipients in several countries. The Independent says it "appears to have been delivered to at least a large number" of app users but that the exact number is unclear. ASOS says it has about 17 million customers a year in more than 150 countries (via The Independent).
- Attribution marker: Infosecurity Magazine reports the message was signed "xuanyewengateway". The Register names the linked Telegram channel "Xuanye Wen Gateway". The two outlets appear to describe the same handle. No outlet links it to a known threat group, and wasteland.me has not been able to attribute it either.
- Company response: The Guardian says ASOS acknowledged the reports but did not confirm or comment further. Reuters and the FT (via The Economic Times) report that ASOS said it was investigating. A BBC reporter asked the ASOS customer service chatbot, which said the company was "aware and investigating". The BBC, The Independent and The Register all said they had no official response at the time of their reports.
- Service status: The Guardian and The Economic Times report that the ASOS website and app stayed online.
What Was Taken
Nothing has been confirmed. The sources agree on the following:
- No outlet has seen data samples, record counts or a leak-site listing. The extortion note gives no volume and does not describe what data it claims to hold.
- The BBC notes it is not publicly known whether ASOS is a Snowflake customer, or what data ASOS might store there.
- The Economic Times reports that some customers removed saved payment methods as a precaution. It stresses that no data loss has been confirmed.
- The Register says the notification "does not, by itself, establish that the sender accessed Asos's Snowflake instance or sensitive customer data."
Analyst assessment: If ASOS does run a Snowflake tenant, retail data warehouses usually hold customer profiles, order histories, contact details and behavioural or marketing data. That makes the claim plausible enough to treat seriously. It is still only a claim. Until ASOS or a regulator says otherwise, treat any data exposure as alleged.
Why It Matters
- The extortion was made public from the start. Extortion groups usually negotiate in private and hope to be paid quietly. The BBC's cyber correspondent describes publishing the demand through the victim's own app as "very unusual". The effect is to apply pressure on ASOS from customers, journalists and investors simultaneously, before any data has been leaked.
- The push channel is now a target in its own right. Charlotte Wilson of Check Point told the BBC that "millions of people trust notifications from apps on their phones because they are supposed to come directly from the company." An attacker who controls that channel can send phishing messages that look exactly like official ones.
- The market reacted before any breach was confirmed. Reported share losses of 5% to 12.5% followed from a single notification. The Independent puts the loss at about £70 million in value. It also notes that ASOS reported 2025 revenue of £2.5 billion and an operating loss of £212 million, so the company was already financially exposed.
- Snowflake tenants are targeted repeatedly. The 2024 campaign against Snowflake customers hit Ticketmaster, Santander, AT&T and dozens of others (The Register, BBC). Connor Riley Moucka later pleaded guilty over a spree that compromised more than 165 organisations and brought in about $2.5 million in ransom payments (The Register). Infosecurity Magazine also notes that in August 2026, Wiz found a critical script injection flaw in one of Snowflake's public GitHub repositories. No source connects that flaw to this incident.
The Attack Technique
The intrusion path has not been disclosed. The available evidence supports these points:
- Two separate systems may be involved. Dan Bird of Horizon3 told the BBC that sending the message "would require access to the company's notification system, which is separate" from Snowflake. The confirmed compromise is therefore of the push or messaging stack. That could mean, for example, a mobile engagement or CRM platform, push provider credentials, or an admin console. The Snowflake compromise is claimed, not shown.
- One possible link between them (analyst inference): If the attackers did get into Snowflake, they may have found credentials or API keys for the notification platform there. Data warehouses often store integration secrets or sit next to marketing tools. The reverse is also possible: attackers who took over the push platform may be overstating how far they got. No source confirms either version.
- The pattern from previous Snowflake breaches: In the 2024 campaign, attackers used credentials stolen by infostealer malware to log in directly to Snowflake tenants that did not enforce MFA (Infosecurity Magazine). Snowflake has since added controls that let administrators require MFA (The Register). Whether ASOS had those controls in place is unknown.
What Organizations Should Do
- Lock down outbound customer messaging. Treat push, SMS and email platforms as production systems that can reach your whole customer base. Require phishing-resistant MFA on every admin console. Rotate and vault server keys for APNs, FCM and any third-party push services. Where the platform supports it, require a second person to approve broadcast sends.
- Enforce MFA and network policies on Snowflake. Require MFA for all human users. Move service accounts to key-pair or OAuth authentication. Apply network policies that restrict logins to known IP ranges. Audit
LOGIN_HISTORYandQUERY_HISTORYfor unfamiliar clients, largeCOPY INTOorGEToperations, and logins from unexpected locations. - Find and remove integration secrets in the data layer. Search warehouses, notebooks, dbt projects and orchestration tools for stored API keys for marketing, CRM or push platforms. Rotate anything you find, and give each integration only the access it needs.
- Watch for infostealer exposure. Check infostealer log feeds for employee and contractor credentials linked to your SaaS tenants. Revoke sessions and rotate credentials as soon as you get a hit. This was how attackers got in during the 2024 Snowflake campaign.
- Set alerts for unusual sends. Alert on broadcasts sent outside normal campaign windows, sends to all users that skip normal segmentation, and message content containing words like "hacked", "leak" or links to Telegram or Tor sites. Make sure there is a tested way to stop all sends immediately.
- Prepare a response for public extortion. Draft holding statements for customers, investors and regulators that can go out within an hour. If your notification channel is compromised, you may need another channel to warn customers not to click links. For UK and EU companies, plan for the ICO's 72-hour GDPR reporting deadline, which applies once a breach is confirmed.
Sources: ASOS app turned into ransom note as hackers claim Snowflake breach | ASOS app users receive notifications from hackers in apparent breach | Asos shoppers sent pop-up message apparently from hackers threateni... | ASOS data breach: ASOS hacked? A threatning 'we will leak it' alert... | ASOS Customers Sent “Hacked” Message Amid Suspected Snowflake Breac... | Asos app delivers a data leak threat instead of fast fashion | Asos customers receive 'hack' notification threatening leak | Asos hacked latest: Customers sent bizarre, threatening notificatio...