Asos Customers Targeted by Threat Actor Claiming Snowflake Data Breach
Asos customers received a rogue notification alleging a breach of the retailer's Snowflake instance, threatening data leaks and causing a temporary stock dip.

Online fashion retailer Asos has become the latest target in a series of threats against companies utilizing cloud data platforms, after its customers reported receiving a disturbing notification. The message, which appeared to originate from a Telegram channel named "Xuanye Wen Gateway," claimed that Asos's Snowflake instance had been compromised and threatened to leak sensitive data.
The notification was specifically addressed to Asos's Data Protection Officer (DPO) and IT team, stating, "Dear ASOS DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it." While the message itself does not confirm that the threat actors actually gained access to Asos's systems or customer data, it was enough to cause concern among customers and investors.
Following the reports of the rogue notification, Asos's share price experienced a temporary decline of approximately 12 percent. Although the stock has since shown some recovery, the incident highlights the potential for even unconfirmed threats to impact market confidence and brand reputation.
The method by which this notification was delivered to Asos customers remains unclear. It is not yet known if the threat actors directly accessed Asos's customer notification systems or if the message was disseminated through other means, such as social media or third-party applications.
This incident echoes a broader trend of threat actors targeting organizations that use Snowflake, a popular cloud-based data warehousing platform. In 2024, numerous high-profile companies, including Ticketmaster, Santander, and AT&T, fell victim to data theft campaigns that exploited vulnerabilities or compromised credentials related to their Snowflake instances.
One notable case involved Connor Riley Moucka, who pleaded guilty to multiple federal charges, including computer fraud and wire fraud, for his role in a hacking spree that compromised over 165 organizations, exposed billions of customer records, and yielded approximately $2.5 million in ransom payments. In response to these widespread attacks, Snowflake has since implemented enhanced security measures, including controls that allow administrators to enforce multi-factor authentication.
Asos and Snowflake have been contacted for comment regarding the incident. The company's response and any further investigation into the validity of the threat will be crucial in understanding the full scope of the potential impact and reinforcing security protocols. The incident serves as a stark reminder of the persistent threats facing cloud-based data storage and the importance of robust security defenses.
This new report details the specific content of the malicious push notification sent to ASOS customers, which falsely claimed a Snowflake compromise and threatened data leaks. It also includes expert commentary from cybersecurity professionals at ESET, Malwarebytes, and Forescout, who discuss the potential implications of such a direct communication to customers and advise on precautions like changing passwords and avoiding suspicious links. The article further emphasizes the need for ASOS to conduct a thorough investigation into the incident.
The new article provides further details on the incident, including the specific wording of the push notification which explicitly mentioned a compromise of a "Snowflake instance" and directed users to a Telegram channel named "Xuanye Group." It also notes that the threat actor claimed payment information was not affected, though no evidence was provided to support this. The rapid stock price drop of ASOS following the notification highlights the immediate market impact of such public-facing threats, even before a full breach confirmation.