Cyber & AI intelligence
Wasteland.
Briefs indexed3027
Issues31
Published Mondays07:30 CT
▣ Breach ASOS-SNOWFLAKE-BRE 2026-10-06

ASOS: App Push Channel Hijacked for Snowflake Extortion Note

"On the morning of Tuesday 6 October 2026, attackers sent a push notification titled "ASOS HACKED" through the official ASOS mobile app to customers' phones. It read: "Dear ASOS DPO and IT, we have fully compromised the…"

On the morning of Tuesday 6 October 2026, attackers sent a push notification titled "ASOS HACKED" through the official ASOS mobile app to customers' phones. It read: "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." The message linked to a Telegram channel. The hijack itself is not in doubt: the BBC, The Guardian, The Register, Infosecurity Magazine and others have all corroborated it from screenshots and customer reports. The claim that ASOS's Snowflake data platform was breached is a separate matter and remains unverified. At the time of writing, no primary source exists. ASOS has published no breach notice, and no regulator filing or Snowflake advisory has appeared. Reuters and the Financial Times (as cited by The Economic Times) and The Guardian report only that ASOS said it was "aware" of the reports and was investigating. The company has not confirmed a cyberattack or any loss of customer data. ASOS shares fell sharply after the notification. Reported figures range from about 5% in the first 30 minutes (IT Security Guru) to almost 12% (The Guardian, The Register) and 12.5%, or about £70 million in market value (The Independent).

What Happened

What Was Taken

Nothing has been confirmed. The sources agree on the following:

Analyst assessment: If ASOS does run a Snowflake tenant, retail data warehouses usually hold customer profiles, order histories, contact details and behavioural or marketing data. That makes the claim plausible enough to treat seriously. It is still only a claim. Until ASOS or a regulator says otherwise, treat any data exposure as alleged.

Why It Matters

The Attack Technique

The intrusion path has not been disclosed. The available evidence supports these points:

What Organizations Should Do

  1. Lock down outbound customer messaging. Treat push, SMS and email platforms as production systems that can reach your whole customer base. Require phishing-resistant MFA on every admin console. Rotate and vault server keys for APNs, FCM and any third-party push services. Where the platform supports it, require a second person to approve broadcast sends.
  2. Enforce MFA and network policies on Snowflake. Require MFA for all human users. Move service accounts to key-pair or OAuth authentication. Apply network policies that restrict logins to known IP ranges. Audit LOGIN_HISTORY and QUERY_HISTORY for unfamiliar clients, large COPY INTO or GET operations, and logins from unexpected locations.
  3. Find and remove integration secrets in the data layer. Search warehouses, notebooks, dbt projects and orchestration tools for stored API keys for marketing, CRM or push platforms. Rotate anything you find, and give each integration only the access it needs.
  4. Watch for infostealer exposure. Check infostealer log feeds for employee and contractor credentials linked to your SaaS tenants. Revoke sessions and rotate credentials as soon as you get a hit. This was how attackers got in during the 2024 Snowflake campaign.
  5. Set alerts for unusual sends. Alert on broadcasts sent outside normal campaign windows, sends to all users that skip normal segmentation, and message content containing words like "hacked", "leak" or links to Telegram or Tor sites. Make sure there is a tested way to stop all sends immediately.
  6. Prepare a response for public extortion. Draft holding statements for customers, investors and regulators that can go out within an hour. If your notification channel is compromised, you may need another channel to warn customers not to click links. For UK and EU companies, plan for the ICO's 72-hour GDPR reporting deadline, which applies once a breach is confirmed.

Sources: ASOS app turned into ransom note as hackers claim Snowflake breach | ASOS app users receive notifications from hackers in apparent breach | Asos shoppers sent pop-up message apparently from hackers threateni... | ASOS data breach: ASOS hacked? A threatning 'we will leak it' alert... | ASOS Customers Sent “Hacked” Message Amid Suspected Snowflake Breac... | Asos app delivers a data leak threat instead of fast fashion | Asos customers receive 'hack' notification threatening leak | Asos hacked latest: Customers sent bizarre, threatening notificatio...