ASOS Hacked: Hackers Send Unauthorized Notifications to App Users, Claiming Snowflake Breach
ASOS is investigating a cyber incident where hackers sent unauthorized app notifications to customers, claiming to have compromised the company's Snowflake data environment.

Fashion retailer ASOS is currently investigating a significant cybersecurity incident that came to light when customers began receiving unauthorized notifications directly through the ASOS app. These alarming messages claimed that hackers had successfully compromised the company's Snowflake data environment and threatened to leak data if ASOS did not engage with them.
The unauthorized notification, which appeared publicly around 10 am on October 6, 2026, was alarming in its directness, addressing ASOS's Data Protection Officer and IT team. It stated, "Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it," and included a link to a Telegram channel. While a screenshot of this notification has circulated, ASOS has confirmed suspicious activity involving third-party communication platforms used for customer outreach, but the claim of a full Snowflake compromise remains unverified.
In response to the incident, ASOS stated that it immediately restricted access to the notification platforms involved. The company is actively working with external cybersecurity specialists and relevant authorities to understand the full scope of the breach. Preliminary assessments suggest that basic personal information, such as names and contact details, may have been accessed. However, ASOS has reassured customers that it does not believe payment card information or account passwords were impacted, though this remains an initial assessment.
The incident has had a notable impact on ASOS's stock, with shares reportedly falling more than 11% following the news. The public nature of the notification, delivered directly to app users, brought the incident to light before the company could fully assess its extent, potentially exacerbating customer concern and market reaction.
This event follows a separate, earlier incident reported on August 25, 2026, where ASOS customer accounts were accessed using compromised login credentials obtained from external sources, likely through credential stuffing attacks. In that case, names, addresses, telephone numbers, dates of birth, and limited payment card details were potentially accessed. ASOS took measures such as blocking affected accounts and requiring password resets. It is important to note that ASOS has stated there is no confirmed link between that previous account access incident and the current investigation into the notification platform.
Snowflake, the cloud data platform mentioned in the hackers' claims, is widely used by businesses for data storage and analysis. However, unauthorized access to a third-party communication platform does not automatically equate to a breach of cloud databases, payment systems, or the broader company network. Cybersecurity experts suggest the attackers may be attempting to pressure ASOS through a public display, rather than having achieved a deep system compromise.
Customers who received the notification are advised to exercise caution, avoid clicking on suspicious links, and remain vigilant for any unusual account activity or unsolicited communications. ASOS has committed to providing further updates as its investigation progresses. The company's website and app are reported to be operating normally.