ASOS "Hacked": What We Know About Today's Snowflake Notification
Just before 10am today, ASOS app users across the UK received a push notification titled "ASOS HACKED," claiming the retailer's Snowflake data platform had been "fully compromised." Here's what's actually been confirmed so far, straight from today's reporting.
Quick answer: what happened today?
At around 10:01am BST on 6 October 2026, a push notification went out through ASOS's own official app, addressed to the retailer's data protection and IT teams, claiming attackers had fully compromised ASOS's Snowflake cloud data environment. It threatened a data leak and linked to a newly created Telegram channel. ASOS says it is investigating. As of now, no breach, data theft or Snowflake compromise has been confirmed.
- How it arrived: through ASOS's genuine app notification system, not a spoofed or lookalike message, which is the most unusual part of this incident.
- What it claimed: that ASOS's Snowflake instance, the cloud platform ASOS uses to store and analyse data, had been fully compromised.
- Market reaction: ASOS shares on the London Stock Exchange fell by roughly 12.5% within hours of the notification going out.
- What's unconfirmed: whether any system was actually breached, whether any data was taken, and who is really behind it.
How This Morning Unfolded
A push notification titled "ASOS HACKED" is sent to app users, addressed directly to ASOS's data protection officer and IT department. It claims the sender has fully compromised ASOS's Snowflake instance and threatens to leak data unless ASOS responds, with a link to a Telegram channel.
Screenshots of the notification begin circulating on Reddit and X, with users in both the UK and US reporting they'd received the same message.
Downdetector logs more than 400 reports flagging issues with the ASOS app, even though the app and website both continue to function normally throughout.
ASOS's share price on the London Stock Exchange drops by around 12.5% as the news spreads, despite no breach having been confirmed.
ASOS acknowledges awareness of the reports and says it is investigating. By the latest reporting, it had not confirmed unauthorised access, data theft, or any compromise of its Snowflake environment.
What the Notification Actually Said
The message was short and, unusually, written as if addressed internally rather than to customers. It referenced ASOS's data protection officer and IT team by role, claimed the sender had fully compromised the company's "Snowflake instance," and told the recipient to engage with the sender or face a leak of the claimed data. The notification linked to a Telegram channel reported to be named "Xuanye Gateway," created the same morning the message went out.
Snowflake, for anyone unfamiliar with the name, is a cloud data platform used by thousands of large organisations, including many retailers, to store and analyse customer and business data at scale. Naming it specifically is notable given its history: a major 2024 extortion campaign against Snowflake customers, using stolen login credentials rather than any flaw in Snowflake itself, led to confirmed breaches at companies including AT&T, Ticketmaster, Neiman Marcus and Advance Auto Parts.
Why This One Is Different From a Typical Phishing Message
Most "you've been hacked" messages consumers receive are phishing attempts impersonating a brand from an external number or email address. What makes today's ASOS notification stand out is that it appears to have come through ASOS's own, genuine app notification system, not a spoofed lookalike. That detail is exactly why it's being taken seriously by security researchers and reporters, even without confirmation of an underlying breach: sending a message through a company's own trusted channel generally requires some form of access to that channel, whether that's a compromise of the notification platform itself, a misused API key, or another route entirely.
What's still genuinely unknown
None of the following has been confirmed as of this writing: whether ASOS's Snowflake environment was actually accessed, whether any customer data was taken, how the notification was actually sent, or who is behind the Telegram channel named in the message. Treat every detail beyond "a notification was sent" as unverified until ASOS says otherwise.
What ASOS Customers Should Do Right Now
✔ Sensible precautions
- Do not click the Telegram link or any link included in the notification.
- Check ASOS's official app, website or verified social accounts for genuine updates, not the notification itself.
- If you're concerned, change your ASOS password, and any other account using the same password, as a precaution.
- Be alert to follow-up phishing emails or texts referencing this incident over the coming days.
✘ Avoid doing this
- Don't assume the claim is true, or false, based on the notification alone.
- Don't enter your ASOS login details anywhere except the official app or asos.com.
- Don't share personal details with anyone contacting you claiming to be "resolving" this incident on ASOS's behalf.
- Don't panic-delete the app; there's no confirmed reason the app itself is unsafe to use.
How Retailers Can Keep Themselves and Customers Secure
Whatever today's claim turns out to be, the incident is a live reminder that a retailer's exposure runs in two directions at once: protecting the systems behind the scenes, and protecting the customers those systems are supposed to serve. Both need attention, not just the one that made headlines.
Securing the business
- Lock down who can send customer messages: know exactly which staff, systems and third-party tools can trigger a push notification, email or SMS from your brand, and review that list regularly.
- Enforce MFA everywhere, especially on cloud data platforms: the 2024 Snowflake campaign succeeded specifically because MFA wasn't switched on for affected accounts.
- Rotate and scope API keys and service accounts tightly: a key with more access than it needs is exactly what turns a minor compromise into a brand-wide incident.
- Have an incident response plan ready: a holding statement, an internal escalation path, and someone authorised to speak publicly, agreed before an incident, not during one.
Protecting customers
- Publish guidance fast, even while investigating: telling customers not to click suspicious links buys time and limits follow-on phishing, regardless of how the main claim resolves.
- Use a consistent, recognisable channel for real updates: customers need to know where genuine company statements will appear, so a fake one is easier to spot.
- Warn specifically about impersonation follow-ups: scammers routinely use a real incident as cover to phish customers in the days after, posing as the retailer's support team.
- Make password resets and breach checks easy to find: a direct link from your homepage or app beats customers searching for help mid-panic.
Most of this comes down to groundwork done before an incident, not during one. Reviewing access to customer-facing systems and building an incident response plan is exactly the kind of work covered by our cyber security audit services and ongoing managed cybersecurity support for retailers.
Frequently Asked Questions
Has ASOS actually been hacked?
As of now, that hasn't been confirmed. ASOS says it's investigating after a push notification claimed a compromise of its Snowflake data platform, but no breach, data theft or system compromise had been verified at the time of writing.
What did the ASOS hack notification say?
It was titled "ASOS HACKED," addressed to ASOS's data protection officer and IT team, and claimed the sender had fully compromised the company's Snowflake instance, threatening a data leak unless ASOS engaged via a linked Telegram channel.
How was the notification sent to customers?
It appears to have been delivered through ASOS's own official app notification system, rather than a spoofed email or text impersonating the brand, which is the most unusual aspect of the incident.
Is my ASOS data at risk?
There's no confirmation that any customer data has been accessed or stolen as a result of today's notification. As a precaution, avoid clicking any links in the message and watch for official updates from ASOS.
What is Snowflake, and why was it named?
Snowflake is a cloud data platform used by many large companies to store and analyse data. It was named in a major 2024 extortion campaign that led to confirmed breaches at several large companies, so referencing it may be intended to lend the claim credibility, whether or not today's claim is accurate.
If You're Reviewing Your Own Exposure
Managed Cybersecurity
Monitoring and access controls for customer-facing platforms and cloud data environments.
View Service → AuditCyber Security Audit
A full review of who can access your cloud platforms and customer-facing notification systems.
View Service → RetailIT Support for Retailers
IT support built around the systems retail and e-commerce businesses depend on.
View Service →Know Who Can Message Your Customers, Before It's Tested
We help retailers audit access to their app, email and notification systems, so a scenario like today's isn't the first time anyone's checked.
Speak With Our Security Team 0161 834 9345